Executive brief
Oracle GoldenGate, a software package used for real-time data integration and replication between databases, contains a vulnerability in its Admin Server component. An attacker with low-level access to the network can exploit this flaw to take complete control of the GoldenGate environment. This could lead to the unauthorized modification of data, theft of sensitive information, or disruption of critical data synchronization processes.
Technical details
A vulnerability exists in the Admin Server Executable component of Oracle GoldenGate. The flaw is categorized as easily exploitable and requires only low-privileged user credentials to execute over a network via HTTPS. Successful exploitation allows an attacker to achieve a complete takeover of the Oracle GoldenGate instance, impacting confidentiality, integrity, and availability. Affected versions include 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle GoldenGate 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60400
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released