Description
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle GoldenGate’s Admin Server contains an exploitable flaw that lets a low‑privileged attacker with network access to the HTTP interface read confidential data. The issue is limited to confidentiality, allowing the attacker to retrieve a subset of data that should be protected. The error does not affect integrity or availability; it results in partial data exposure.

Affected Systems

Oracle Corporation’s Oracle GoldenGate product is affected. Versions 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1 are impacted.

Risk and Exploitability

The CVSS v3.1 score of 4.3 classifies this issue as low severity, reflecting that the only impact is a partial breach of confidentiality. The EPSS score of less than 1% indicates a very low probability that an attacker will exploit this vulnerability, and it is not listed in CISA’s KEV catalog. The likely attack vector is remote, requiring network access to the Admin Server’s HTTP endpoint; the flaw can be exploited by a low‑privileged attacker without the need for credentials or elevated privileges.

Generated by OpenCVE AI on August 4, 2026 at 04:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a patched version of Oracle GoldenGate that addresses this vulnerability.
  • Restrict HTTP access to the Admin Server by limiting firewall rules or placing the service behind a VPN or internal network zone to allow only trusted hosts.
  • Enforce strict role‑based access control and remove unnecessary data read permissions for accounts that interact with the Admin Server.

Generated by OpenCVE AI on August 4, 2026 at 04:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Unauthorized Data Read in Oracle GoldenGate

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP-based Data Access Vulnerability in Oracle GoldenGate Admin Server

Sun, 26 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP-based Data Access Vulnerability in Oracle GoldenGate Admin Server

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle goldengate
CPEs cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Goldengate
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:40:01.691Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60395

cve-icon Vulnrichment

Updated: 2026-07-24T16:38:34.511Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor