Executive brief
Oracle GoldenGate, a software package used for real-time data integration and replication, contains a vulnerability in its Admin Server component. An unauthenticated attacker could exploit this over the network to gain unauthorized access to a subset of the data managed by the system. This could lead to the exposure of sensitive business information or configuration details.
Technical details
A vulnerability exists in the Admin Server Executable component of Oracle GoldenGate versions 21.3-21.21 and 23.4-23.26.1. The flaw is classified as easily exploitable and allows an unauthenticated attacker with network access via HTTPS to compromise the system. The impact is limited to unauthorized read access (Confidentiality) of a subset of Oracle GoldenGate accessible data. The vulnerability has a CVSS 3.1 base score of 5.3, reflecting low complexity and no requirement for user interaction or privileges. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle GoldenGate 21.3-21.21, 23.4-23.26.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date