Oracle GG AdminServer exec unauth access, 19.123.26.1, partial DOS
CVE-2026-60397 Published on July 21, 2026
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate executes to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Vulnerability Analysis
Weakness Type
Improper Resource Shutdown or Release
The program does not release or incorrectly releases a resource before it is made available for re-use. When a resource is created or allocated, the developer is responsible for properly releasing the resource as well as accounting for all potential paths of expiration or invalidation, such as a set period of time or revocation.
Products Associated with CVE-2026-60397
stack.watch emails you whenever new vulnerabilities are published in Oracle Goldengate or Oracle. Just hit a watch button to start following.
Affected Versions
Oracle Corporation Oracle GoldenGate:- Version 19.1.0.0.0, <= 19.30.0.0 is affected.
- Version 21.3, <= 21.21 is affected.
- Version 23.4, <= 23.26.1 is affected.