CVE-2026-60394: Infoleak
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60394?
CVE-2026-60394 has a medium severity rating of 5.3.
How do I fix CVE-2026-60394?
To fix CVE-2026-60394, ensure you update Oracle GoldenGate to the latest supported version.
What components are affected by CVE-2026-60394?
CVE-2026-60394 affects the Admin Server Executable component of Oracle GoldenGate.
Who is vulnerable to CVE-2026-60394?
Unauthenticated attackers with network access via HTTPS to Oracle GoldenGate versions 21.3-21.21 and 23.4-23.26.1 are vulnerable to CVE-2026-60394.
What types of attacks can result from CVE-2026-60394?
Exploitation of CVE-2026-60394 can lead to unauthorized disclosure of information, compromising the Oracle GoldenGate environment.