Description
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the libraries component of Oracle GoldenGate permits an attacker who has logged on with low privileges to the underlying infrastructure to compromise the GoldenGate instance. By exploiting this weakness the attacker can gain full control over the service, resulting in loss of confidentiality, integrity, and availability. The weakness is essentially a local privilege escalation that can evolve into arbitrary code execution, normally categorized as CWE-284 – Improper Access Control.

Affected Systems

This issue affects Oracle GoldenGate products from Oracle Corporation. The specific affected releases are 23.4 through 23.26.1. Users running these versions should verify that they are not using any vulnerable libraries and consider updating to a non‑affected release.

Risk and Exploitability

The CVSS v3.1 base score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests current exploitation likelihood is low, and the vulnerability is not listed in CISA’s KEV catalog. Attack requires the attacker to have some local presence on the host that runs GoldenGate; no user interaction is required and the attack vector is local. If successful, the attacker can reconfigure, replace, or shut down GoldenGate, creating a full compromise of the data replication process.

Generated by OpenCVE AI on August 4, 2026 at 17:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle GoldenGate to a release that excludes the vulnerable libraries (consult Oracle for the latest patches).
  • If an upgrade is not immediately possible, restrict local logon permissions for the user account under which GoldenGate runs, limiting filesystem access and sudo rights.
  • Monitor GoldenGate logs and system activity for signs of unauthorized configuration changes or process execution to detect potential compromise early.

Generated by OpenCVE AI on August 4, 2026 at 17:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle GoldenGate Libraries

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle GoldenGate Libraries

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Takeover via Oracle GoldenGate Libraries
Weaknesses CWE-285

Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Takeover via Oracle GoldenGate Libraries
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle goldengate
CPEs cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Goldengate
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T14:52:05.424Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60570

cve-icon Vulnrichment

Updated: 2026-07-27T14:51:55.952Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses