PatchSiren cyber security CVE debrief
CVE-2026-60399 Oracle Corporation CVE debrief
CVE-2026-60399 is a vulnerability in the Receiver Service Executable component of Oracle GoldenGate, a data integration platform. This vulnerability has a CVSS 3.1 Base Score of 6.5 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a complete DOS of Oracle GoldenGate. Organizations should review their deployments and assess the risk of this vulnerability. The CVE record was published on 2026-07-21T22:17:42.383Z and has not been modified since then. The vulnerability affects Oracle GoldenGate versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1.
- Vendor
- Oracle Corporation
- Product
- Oracle GoldenGate
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-31
Who should care
Organizations using Oracle GoldenGate versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1 should prioritize patching or mitigating this vulnerability to prevent potential DOS attacks. This includes operators, platform administrators, vulnerability management teams, and security teams responsible for ensuring the security and integrity of their Oracle GoldenGate deployments. Additionally, security teams should review their monitoring and detection capabilities to ensure they can identify potential exploitation attempts. IT teams responsible for change management and patching should also be aware of this vulnerability and plan for the necessary updates or mitigations. Finally, asset owners and system administrators should verify their inventory of Oracle GoldenGate deployments and assess their exposure to this vulnerability. They should also review their incident response plans to ensure they are prepared to respond to potential exploitation incidents. Security teams should also consider implementing compensating controls, such as network access restrictions and monitoring, to reduce the risk of exploitation while patches are being applied. Furthermore, organizations should track exceptions, retest remediated assets, and close the item only after evidence is documented. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Reviewing the supplied official advisory or CVE record can help validate affected scope, severity, and vendor guidance. Planning vendor-supported updates or mitigations through normal change control where exposure is confirmed is also crucial. Checking relevant monitoring, detection, and logs for exposed assets that need extra review is essential. Finally, organizations should consider implementing asset inventory and source tracking to ensure they can identify and manage their Oracle GoldenGate deployments effectively. Rolling back change windows and implementing source tracking can also help minimize the impact of potential exploitation incidents. By taking these steps, organizations can reduce the risk of exploitation and ensure the security and integrity of их_>
Technical summary
CVE-2026-60399 is a vulnerability in the Receiver Service Executable component of Oracle GoldenGate. It has a CVSS 3.1 Base Score of 6.5 and can be exploited by a low-privileged attacker with network access via HTTP, potentially leading to a complete DOS of Oracle GoldenGate. The vulnerability affects Oracle GoldenGate versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1. The vulnerability can be mitigated by applying patches or updates provided by Oracle.
Defensive priority
Medium priority given the CVSS score of 6.5 and the potential for a complete DOS of Oracle GoldenGate.
Recommended defensive actions
- Inventory and verify Oracle GoldenGate versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1 are in use
- Apply patches or updates provided by Oracle to address CVE-2026-60399
- Implement compensating controls such as network access restrictions and monitoring
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE-2026-60399 vulnerability affects Oracle GoldenGate versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1. It allows a low-privileged attacker with network access via HTTP to compromise Oracle GoldenGate, potentially causing a hang or frequently repeatable crash (complete DOS). The CVSS 3.1 Base Score is 6.5 (Availability impacts).
Official resources
-
CVE-2026-60399 CVE record
CVE.org
-
CVE-2026-60399 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:42.383Z and has not been modified since then.