Executive brief
Oracle GoldenGate, a software suite used for real-time data integration and replication, contains a vulnerability in its configuration service. An unauthenticated attacker could exploit this over a network to gain full control of the GoldenGate environment. This could lead to the unauthorized access, modification, or deletion of critical business data being synchronized across the enterprise.
Technical details
A vulnerability exists in the Config Service Executable component of Oracle GoldenGate versions 23.4 through 23.26.2. The flaw is exploitable by an unauthenticated attacker with network access via HTTP. While the attack complexity is rated as high, suggesting specific conditions or timing may be required for success, a successful exploit results in a complete takeover of the Oracle GoldenGate instance. This impacts the confidentiality, integrity, and availability of the system. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle GoldenGate 23.4 through 23.26.2
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication