Junglewise Threat Intelligence

CVE-2026-47022: Oracle GoldenGate Stream Analytics denial of service in Security component

CVE-2026-47022 · Severity: low · CVSS 3.3 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle GoldenGate Stream Analytics, a tool used for real-time data processing and analysis, contains a security vulnerability. An attacker with existing low-level access to the underlying server can exploit this flaw to disrupt the application's operations. This could lead to a partial service outage, affecting the organization's ability to process data streams reliably.

Technical details

A vulnerability exists in the Security component of Oracle GoldenGate Stream Analytics version 26.1.0.0.0. The flaw is categorized as easily exploitable and requires the attacker to have local logon credentials to the infrastructure where the software is running. Successful exploitation allows a low-privileged user to impact the availability of the service, resulting in a partial denial of service (DoS). The vulnerability has been assigned a CVSS 3.1 base score of 3.3, reflecting low impact on availability with no impact on confidentiality or integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle GoldenGate Stream Analytics 26.1.0.0.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References