Junglewise Threat Intelligence

CVE-2026-60396: Oracle GoldenGate takeover via Distribution Server executable

CVE-2026-60396 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle GoldenGate. Vendors: Oracle.

Executive brief

Oracle GoldenGate, a software package used for real-time data integration and replication between databases, contains a vulnerability in its Distribution Server component. A high-privileged attacker can exploit this flaw over a network to take full control of the GoldenGate environment. This could lead to the unauthorized access, modification, or deletion of sensitive business data being synchronized across the enterprise.

Technical details

This vulnerability exists within the Distribution Server executable component of Oracle GoldenGate. It is classified as easily exploitable, requiring a high-privileged account to initiate the attack over the network via HTTPS (AV:N/AC:L/PR:H/UI:N). Successful exploitation allows an attacker to fully compromise the Oracle GoldenGate instance, impacting confidentiality, integrity, and availability. The issue affects versions 21.3-21.21 and 23.4-23.26.1. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle GoldenGate 21.3-21.21, 23.4-23.26.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle and NVD publication.

References

Related threats