CVE-2026-60394Medium· 5.3▾ SunlitVulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTT…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.3%
Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 21.3-21.21 and 23.4-23.26.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
goldengate >= 21.3.0, <= 21.21.0.0.0goldengate >= 23.4, <= 23.26.1.0.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-60395Medium· 4.3Vulnerability in Oracle GoldenGate (component: Admin Server Executable)
CVE-2026-60400High· 8.8Vulnerability in Oracle GoldenGate (component: Admin Server Executable)
CVE-2026-60399Medium· 6.5Vulnerability in Oracle GoldenGate (component: Receiver Service Executable)
CVE-2026-60397Medium· 4.3Vulnerability in Oracle GoldenGate (component: Admin Server Executable)
CVE-2026-60396High· 7.2Vulnerability in Oracle GoldenGate (component: Distribution Server executable)
CVE-2026-22016High· 7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP)