---
id: CVE-2026-60396
title: 'Vulnerability in Oracle GoldenGate (component: Distribution Server executable)'
summary: >-
  Vulnerability in Oracle GoldenGate (component: Distribution Server
  executable).  Supported versions that are affected are 21.3-21.21 and 
  23.4-23.26.1. Easily exploitable vulnerability allows high privileged attacker
  with network access …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: oracle
product: goldengate
affected:
  - 'goldengate >= 21.3.0, <= 21.21.0.0.0'
  - 'goldengate >= 23.4, <= 23.26.1.0.0'
published: '2026-07-21'
updated: '2026-07-31'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-60396'
references:
  - url: 'https://www.oracle.com/security-alerts/cpujul2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
epss: 0.00486
epssPercentile: 0.40946
ingestedAt: '2026-08-01T14:12:57.819Z'
---

## Overview

Vulnerability in Oracle GoldenGate (component: Distribution Server executable).  Supported versions that are affected are 21.3-21.21 and  23.4-23.26.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

## Affected

- `goldengate >= 21.3.0, <= 21.21.0.0.0`
- `goldengate >= 23.4, <= 23.26.1.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
