Executive brief
Oracle GoldenGate is a software package used for real-time data integration and replication between databases. A vulnerability in its Microservices component allows an attacker with basic user access to take full control of the application over the network. This could lead to the unauthorized modification of sensitive data, theft of information, or a complete shutdown of data synchronization services.
Technical details
A vulnerability in the Oracle GoldenGate Microservices component allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation grants the attacker full control over the Confidentiality, Integrity, and Availability of the affected GoldenGate instance. The vulnerability affects versions 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle GoldenGate 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory