Executive brief
Oracle GoldenGate, a software suite for real-time data integration and replication, contains a vulnerability in its Service Manager component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the GoldenGate environment. This could lead to the unauthorized access, modification, or deletion of sensitive business data being synchronized across the organization.
Technical details
A vulnerability exists in the Service Manager component of Oracle GoldenGate across multiple versions (19c, 21c, and 23c). The flaw is characterized by low attack complexity and requires only low-privileged user credentials to exploit. An attacker can reach the vulnerable component over the network via HTTP. Successful exploitation allows for a complete takeover of the Oracle GoldenGate instance, impacting the confidentiality, integrity, and availability of the system. Users are advised to consult the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle GoldenGate 19.1.0.0.0-19.29.0.0, 21.3-21.21, 23.4-23.26.1.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published