Executive brief
Oracle GoldenGate, a software suite for real-time data integration and replication, contains a vulnerability in its Admin Server component. An attacker located on the same local network as the server could exploit this flaw to disrupt the service. While this does not allow for data theft, it can cause a partial denial of service, potentially delaying critical data synchronization tasks.
Technical details
A vulnerability exists in the Admin Server Executable component of Oracle GoldenGate. The flaw is classified as easily exploitable and requires the attacker to have access to the adjacent physical communication segment (local network) where the software is running. No authentication or user interaction is required for exploitation. A successful attack results in a partial denial of service (DoS), impacting the availability of the GoldenGate service. The vulnerability affects versions 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1.
Affected products
- Oracle GoldenGate 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this advisory.
- 2026-07-21: disclosed