Description
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Corporation's Oracle GoldenGate Admin Server Executable contains a flaw that allows an unauthenticated attacker with physical access to the communication segment attached to the hardware where GoldenGate runs to compromise the application. The vulnerability is an easy‑to‑exploit local issue that can produce a partial denial of service, reducing the availability of the GoldenGate processing engine and disrupting data replication. The weakness is a form of failure to properly manage resources, identified as CWE‑404, indicating insufficient resource handling.

Affected Systems

Oracle Corporation’s Oracle GoldenGate, versions 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1 are vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 4.3 indicates a low‑severity availability impact, and the EPSS score of less than 1 % combined with the absence from CISA’s KEV catalogue suggests exploitation is unlikely at present. Because the attack requires local or intra‑segment physical access to the hardware that hosts GoldenGate, the likely attack vector is “Local Access” via the communication segment. No remote exploitation path, integrity, or confidentiality compromise is documented.

Generated by OpenCVE AI on August 4, 2026 at 17:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle GoldenGate update that includes the security fix for CVE‑2026‑60397, if one is available from Oracle.
  • Restrict physical access to the network hardware and communication segments that interface with Oracle GoldenGate.
  • Implement network segmentation or isolate GoldenGate servers from general network traffic.
  • Enable monitoring of GoldenGate process health and logs to detect abnormal termination or compromise attempts.
  • Consider deploying redundant GoldenGate instances or a fail‑over strategy to mitigate partial service disruptions.

Generated by OpenCVE AI on August 4, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Denial of Service via Admin Server in Oracle GoldenGate

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Denial of Service via Admin Server in Oracle GoldenGate

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access Denial of Service in Oracle GoldenGate
Weaknesses CWE-278
CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access Denial of Service in Oracle GoldenGate
Weaknesses CWE-278
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle goldengate
CPEs cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Goldengate
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:29:55.190Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60397

cve-icon Vulnrichment

Updated: 2026-07-24T16:29:46.653Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release