CVE-2026-60400: High severity Oracle Oracle GoldenGate vulnerability
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply network-level access restrictions to Oracle GoldenGate Admin Server Executable so the HTTPS service is not reachable from untrusted networks (limit inbound access to trusted sources only).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60400?
The severity of CVE-2026-60400 is rated as high with a CVSS score of 8.8.
How do I fix CVE-2026-60400?
To fix CVE-2026-60400, update your Oracle GoldenGate to a supported version that addresses the vulnerability.
Who is affected by CVE-2026-60400?
CVE-2026-60400 affects users of Oracle GoldenGate versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1.
What type of access is required to exploit CVE-2026-60400?
CVE-2026-60400 can be exploited by a low privileged attacker with network access via HTTPS.
What components are impacted by CVE-2026-60400?
CVE-2026-60400 impacts the Admin Server Executable component of Oracle GoldenGate.