Description
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Oracle GoldenGate Admin Server Executable and allows an unauthenticated attacker who can reach the system over HTTPS to read a subset of data exposed by the GoldenGate instance. The vulnerability is classified as a medium‑severity flaw with a CVSS v3.1 Base Score of 5.3 that reflects a Confidentiality impact only. Because integrity and availability are not affected, the compromise is limited to data leakage.

Affected Systems

Oracle GoldenGate products version 21.3 through 21.21 and 23.4 through 23.26.1 are affected. Any installation of these releases with an exposed Admin Server is vulnerable until a vendor-supplied patch is applied.

Risk and Exploitability

The flaw can be exploited remotely over the network without authentication, making it accessible to any machine that can reach the Admin Server via HTTPS. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker can gain read-only access to sensitive GoldenGate data, potentially exposing confidential information. Prompt patching or mitigation is recommended to eliminate this risk.

Generated by OpenCVE AI on August 2, 2026 at 22:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle GoldenGate security patch that addresses the Admin Server flaw.
  • Restrict HTTPS access to the Admin Server by configuring firewall rules or VPNs so that only authorized management IPs can connect.
  • Monitor GoldenGate logs and network traffic for unexpected HTTPS requests to the Admin Server and investigate any anomalies promptly.

Generated by OpenCVE AI on August 2, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Read Vulnerability in Oracle GoldenGate Admin Server

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Read Vulnerability in Oracle GoldenGate Admin Server

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Data Read in Oracle GoldenGate Admin Server
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Data Read in Oracle GoldenGate Admin Server
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle goldengate
CPEs cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Goldengate
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:44:25.915Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60394

cve-icon Vulnrichment

Updated: 2026-07-24T16:42:57.331Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor