Junglewise Threat Intelligence

CVE-2026-60395: Oracle GoldenGate information disclosure in Admin Server Executable

CVE-2026-60395 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Technologies: Oracle GoldenGate. Vendors: Oracle.

Executive brief

Oracle GoldenGate is a software package used for real-time data integration and replication between databases. A vulnerability in its Admin Server component could allow an authorized user with low-level permissions to view sensitive data they are not supposed to see. This could lead to the exposure of internal configuration or business data managed by the replication service.

Technical details

An information disclosure vulnerability exists in the Admin Server Executable component of Oracle GoldenGate. The flaw is easily exploitable by a low-privileged attacker with network access via the HTTP protocol. Successful exploitation does not require user interaction and allows the attacker to read a subset of data accessible to the GoldenGate service. Affected versions include the 19c, 21c, and 23c release trains. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle GoldenGate 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats