CVE-2026-60400
Analyzed Analyzed - Analysis Complete

Oracle GoldenGate Admin Server Takeover Vulnerability

Vulnerability report for CVE-2026-60400, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-07-31

Assigner: Oracle

Description

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-07-31
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
oracle goldengate From 23.4 (inc) to 23.26.1.0.0 (inc)
oracle goldengate From 19.1.0.0.0 (inc) to 19.30.0.0 (inc)
oracle goldengate From 21.3.0 (inc) to 21.21.0.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle GoldenGate's Admin Server Executable affecting versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1. It allows a low-privileged attacker with network access via HTTPS to compromise the system and potentially take over Oracle GoldenGate entirely.

Detection Guidance

Detecting this vulnerability requires checking for Oracle GoldenGate versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, or 23.4-23.26.1. Verify installed versions using commands like 'ggsci version' or checking Oracle GoldenGate directories for version files. Monitor network traffic for unusual HTTPS connections to the Admin Server.

Impact Analysis

Successful exploitation could lead to complete takeover of Oracle GoldenGate, resulting in unauthorized access, data breaches, or disruption of data replication services. This could affect data integrity, confidentiality, and availability for systems relying on GoldenGate.

Compliance Impact

The vulnerability allows low-privileged attackers to compromise Oracle GoldenGate via HTTPS, potentially leading to unauthorized access and control. This could result in unauthorized data access, modification, or deletion, which may violate GDPR (data protection) and HIPAA (health data confidentiality) compliance requirements.

Mitigation Strategies

Apply the latest Oracle GoldenGate patches for affected versions (19.1.0.0.0-19.30.0.0, 21.3-21.21, 23.4-23.26.1) as soon as possible. Restrict network access to the Admin Server via HTTPS and enforce least privilege for user accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-60400. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart