Description
Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservices). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker who can reach Oracle GoldenGate Microservices over HTTP can exploit an easily‑exploitable vulnerability that allows complete takeover of the GoldenGate instance. The flaw provides full confidentiality, integrity, and availability compromise, effectively granting the attacker unrestricted control over the system.

Affected Systems

Oracle GoldenGate Microservices is the affected component. The vulnerability impacts the following version ranges: 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1. Any installation of these versions is at risk and should be verified against the affected list.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates high severity; the EPSS score of less than 1 % suggests a low probability of exploitation in the general population, yet the impact of a successful attack is severe. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request sent from a low‑privileged network user, with the attacker potentially providing crafted input that the service processes without adequate validation. Given the high impact scores, the risk remains significant for any systems still running the affected versions and should not be ignored.

Generated by OpenCVE AI on August 2, 2026 at 22:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle GoldenGate patch that addresses the remote code execution flaw
  • Configure firewall or network ACLs to restrict HTTP access to the GoldenGate Microservices only to trusted hosts and block unsolicited traffic
  • Monitor GoldenGate logs for anomalous authentication attempts or unexpected process activity and perform incident response if intrusion indicators are detected

Generated by OpenCVE AI on August 2, 2026 at 22:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle GoldenGate Microservices via Unvalidated HTTP Input

Tue, 28 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title High‑Impact Remote Code Execution in Oracle GoldenGate Microservices via HTTP
Weaknesses CWE-20
CWE-78

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title High‑Impact Remote Code Execution in Oracle GoldenGate Microservices via HTTP
Weaknesses CWE-20
CWE-78

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate Microservices). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle goldengate
CPEs cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Goldengate
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:29:11.741Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60398

cve-icon Vulnrichment

Updated: 2026-07-24T16:29:04.170Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function