Description
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data as well as unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Oracle GoldenGate libraries and permits a local user with logon to the infrastructure where GoldenGate runs to perform unauthorized create, update, delete and read operations on data the product can access. This represents a CWE‑284 improper access control weakness. The attacks allow modification of data and reading of sensitive information with low confidentiality and integrity impact.

Affected Systems

Oracle Corporation's Oracle GoldenGate is affected across multiple major releases. Already listed vulnerable version ranges are 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.2. No version suffix information is supplied beyond these ranges.

Risk and Exploitability

The CVSS v3.1 base score is 4.4 with a local attack vector, low access complexity, low privilege requirement and no user interaction, reflecting an easier exploitation for a local low‑privileged attacker. The EPSS score is less than 1%, indicating a very low probability of exploitation at the current time, and the vulnerability has not been listed in CISA's KEV catalog. The likely attack path involves a local user gaining privileges to execute GoldenGate processes and leveraging the libraries’ lack of proper access checks to manipulate accessible data.

Generated by OpenCVE AI on August 2, 2026 at 20:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle GoldenGate to a version that is newer than 19.30.0.0, 21.21, or 23.26.2 as recommended by Oracle's CPU July 2026 advisory.
  • Apply any interim fixes or work‑arounds that Oracle has supplied by reviewing the CPU July 2026 advisory for step‑by‑step guidance.
  • Limit local system access by enforcing least‑privilege principles for accounts that can execute Oracle GoldenGate binaries, and segregate the GoldenGate environment from other infrastructure to reduce attack surface.
  • If an update is not immediately available, monitor Oracle product release activity and apply future patches as soon as they are released to eliminate improper access control in the libraries.

Generated by OpenCVE AI on August 2, 2026 at 20:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploitation Enables Unauthorized Data Modification and Read in Oracle GoldenGate

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Flaw Enables Unauthorized Data Operations in Oracle GoldenGate
Weaknesses CWE-862

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Flaw Enables Unauthorized Data Operations in Oracle GoldenGate
Weaknesses CWE-862

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data as well as unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle goldengate
CPEs cpe:2.3:a:oracle:goldengate:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle goldengate
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Goldengate
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:16:24.661Z

Reserved: 2026-07-08T15:51:55.612Z

Link: CVE-2026-61084

cve-icon Vulnrichment

Updated: 2026-07-23T19:16:19.829Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:39.323

Modified: 2026-08-06T15:11:29.927

Link: CVE-2026-61084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses