CVE-2026-61106: High severity Oracle Oracle GoldenGate vulnerability
Vulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.4-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61106?
CVE-2026-61106 has a severity rating of high with a score of 8.1.
Who is affected by CVE-2026-61106?
CVE-2026-61106 affects users of Oracle GoldenGate versions 23.4 to 23.26.2.
How do I fix CVE-2026-61106?
To fix CVE-2026-61106, it is recommended to apply the latest security patch provided by Oracle.
What type of attackers can exploit CVE-2026-61106?
CVE-2026-61106 can be exploited by unauthenticated attackers with network access via HTTP.
What components of Oracle GoldenGate are impacted by CVE-2026-61106?
CVE-2026-61106 specifically impacts the Config Service Executable component of Oracle GoldenGate.