CVE-2026-60400

Oracle · GoldenGate

A vulnerability in the Oracle GoldenGate Admin Server allows a low privileged attacker with network access to compromise the application.

Executive summary

An easily exploitable security vulnerability in Oracle GoldenGate allows authenticated attackers to achieve full system takeover.

Vulnerability

This is an easily exploitable flaw within the Admin Server component that permits a low privileged user with HTTPS network access to execute unauthorized actions, leading to a complete compromise of the GoldenGate instance.

Business impact

Successful exploitation of this vulnerability poses a severe risk to data integrity and system availability. With a CVSS score of 8.8, the potential for unauthorized administrative takeover means an attacker could exfiltrate sensitive data, manipulate database replication streams, or disrupt critical business operations.

Remediation

Immediate Action: Apply the security updates provided in the July 2026 Oracle Critical Patch Update immediately.

Proactive Monitoring: Review access logs for the Admin Server for suspicious HTTP requests originating from low privileged user accounts.

Compensating Controls: Restrict network access to the Admin Server interface to trusted management subnets using firewalls or VPNs to limit the exposure of the management port.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for full system takeover, organizations must prioritize patching this vulnerability. Administrators should verify their current GoldenGate version against the affected ranges and apply the vendor-supplied security updates as soon as they are available.