Executive brief
Oracle GoldenGate, a software suite used for real-time data integration and replication, contains a vulnerability in its library components. An attacker who already has basic access to the underlying server can exploit this to view, modify, or delete sensitive data managed by the application. This could lead to unauthorized data manipulation or the exposure of confidential business information.
Technical details
A vulnerability exists in the Libraries component of Oracle GoldenGate. The flaw is categorized as easily exploitable by a low-privileged attacker with local logon access to the infrastructure where GoldenGate is executing. Successful exploitation allows the attacker to compromise the integrity and confidentiality of the system by performing unauthorized updates, inserts, or deletions of data, as well as unauthorized read access to a subset of data. The attack vector is local (AV:L) and requires no user interaction. Fixes are typically delivered via Oracle's Critical Patch Update (CPU) program.
Affected products
- Oracle GoldenGate 19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.2
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
- 2026-07-21: disclosed