Oracle GoldenGate Stream Analytics 26.1.0.0.0 Security: Low Priv Lateral Attacks
CVE-2026-47022 Published on July 21, 2026
Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Security). The supported version that is affected is 26.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where GoldenGate Stream Analytics executes to compromise GoldenGate Stream Analytics. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 3.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).
Vulnerability Analysis
CVE-2026-47022 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
What is a Resource Exhaustion Vulnerability?
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVE-2026-47022 has been classified to as a Resource Exhaustion vulnerability or weakness.
Products Associated with CVE-2026-47022
stack.watch emails you whenever new vulnerabilities are published in Oracle Goldengate Stream Analytics or Oracle. Just hit a watch button to start following.
Affected Versions
Oracle Corporation GoldenGate Stream Analytics Version 26.1.0.0.0 is affected by CVE-2026-47022Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.