Description
Vulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle GoldenGate’s Distribution Server executable contains a vulnerability that enables an attacker with network access over HTTPS to execute code with high privileges, potentially leading to a full takeover of the GoldenGate service. The CVSS v3.1 base score of 7.2 reflects significant impacts on confidentiality, integrity, and availability.

Affected Systems

Affected Oracle GoldenGate versions are 21.3 through 21.21 and 23.4 through 23.26.1. Any installation of these releases deployed in an environment where an attacker can reach the HTTPS endpoint is considered vulnerable.

Risk and Exploitability

The vulnerability is considered remotely exploitable, requiring the attacker to send crafted requests over HTTPS. With an EPSS score of less than 1%, real-world exploitation is unlikely at present, and the issue is not listed in the CISA KEV catalog. However, the severe impact makes patching a priority.

Generated by OpenCVE AI on August 4, 2026 at 04:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle GoldenGate to a version outside the affected ranges (e.g., 21.22 or later, or 23.27 or later).
  • Where upgrading is not feasible, restrict HTTPS access to the Distribution Server to trusted, internal hosts using firewall or network access control lists.
  • Ensure that the HTTPS service requires strong authentication and proper certificate validation to prevent unauthorized connections.

Generated by OpenCVE AI on August 4, 2026 at 04:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title High Privilege Remote Code Execution via HTTPS in Oracle GoldenGate Distribution Server

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title High Privilege HTTPS Attack Enables Complete Oracle GoldenGate Takeover
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title High Privilege HTTPS Attack Enables Complete Oracle GoldenGate Takeover
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle GoldenGate (component: Distribution Server executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle goldengate
CPEs cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Goldengate
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-25T03:55:32.397Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60396

cve-icon Vulnrichment

Updated: 2026-07-24T16:32:53.843Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function