Oracle GoldenGate: denial of service
Medium4.3CVE-2026-60397 · Published Jul 21, 2026 · updated Jul 31, 2026
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Oracle GoldenGate Product | >= 19.1.0.0.0, <= 19.30.0.0 | No fix yet |
| >= 21.3, <= 21.21 | No fix yet | |
| >= 23.4, <= 23.26.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-404
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 21 | Oracle HRMS (US): takeover via Internal Operations | High7.8 | No fix yet |
| Jul 21 | Oracle HRMS (US): data exposure via Internal Operations | Medium6.5 | No fix yet |
| Jul 21 | Oracle Work in Process: data tampering via Internal Operations | Medium5.4 | No fix yet |
| Jul 21 | Oracle HRMS (US): data tampering via US Payroll Year End | High7.1 | No fix yet |
| Jul 21 | Oracle HRMS (UK): data exposure via UK Payroll | High7.7 | No fix yet |
| Jul 21 | Oracle Java SE: takeover via Install | High7.8 | No fix yet |