CVE-2026-60399: Medium severity Oracle Oracle GoldenGate (Receiver Service Executable) vulnerability
Vulnerability in Oracle GoldenGate (component: Receiver Service Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle GoldenGate (Receiver Service Executable)to a version that resolves this vulnerability.Fixed in 21.21 - Upgrade
Upgrade
Oracle GoldenGate (Receiver Service Executable)to a version that resolves this vulnerability.Fixed in 23.26.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60399?
The severity of CVE-2026-60399 is rated medium with a CVSS score of 6.5.
How do I fix CVE-2026-60399?
To fix CVE-2026-60399, you should apply the latest patch provided by Oracle for affected versions of GoldenGate.
What systems are affected by CVE-2026-60399?
CVE-2026-60399 affects Oracle GoldenGate versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1.
What type of attack is possible with CVE-2026-60399?
CVE-2026-60399 allows a low privileged attacker with network access via HTTP to compromise Oracle GoldenGate.
When was CVE-2026-60399 published?
CVE-2026-60399 was published on July 21, 2026.