PatchSiren cyber security CVE debrief
CVE-2026-60400 Oracle CVE debrief
The CVE-2026-60400 vulnerability is in the Admin Server Executable component of Oracle GoldenGate, a high-severity issue allowing low-privileged attackers with network access via HTTPS to potentially take over the system. Affected versions include 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1. Oracle GoldenGate administrators should review and apply security patches, restrict network access, and monitor for suspicious activity.
- Vendor
- Oracle
- Product
- GoldenGate
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-31
Who should care
Oracle GoldenGate administrators, security teams, and IT professionals responsible for Oracle products should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing and applying security patches, restricting network access, and monitoring for suspicious activity. The vulnerability's high severity and potential for system takeover necessitate prompt attention from those responsible for Oracle GoldenGate installations and overall security posture within their organizations.
Technical summary
The CVE-2026-60400 vulnerability in Oracle GoldenGate's Admin Server Executable has a CVSS 3.1 Base Score of 8.8, indicating high severity. Low-privileged attackers with network access via HTTPS can compromise Oracle GoldenGate, potentially leading to a takeover. Affected versions are 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1. The vulnerability allows for easy exploitation, emphasizing the need for immediate patching and defensive measures.
Defensive priority
Oracle GoldenGate vulnerability allows low-privileged attackers to compromise the system via HTTPS, leading to potential takeover.
Recommended defensive actions
- Review and apply Oracle's security patches for affected Oracle GoldenGate versions.
- Restrict network access to Oracle GoldenGate Admin Server Executable.
- Monitor for suspicious activity and implement compensating controls.
- Verify inventory of Oracle GoldenGate installations and their versions.
- Consider implementing additional security measures for low-privileged accounts.
Evidence notes
The CVE-2026-60400 vulnerability affects Oracle GoldenGate versions 19.1.0.0.0-19.30.0.0, 21.3-21.21, and 23.4-23.26.1. It allows low-privileged attackers with network access via HTTPS to compromise Oracle GoldenGate, potentially leading to a takeover. The CVSS 3.1 Base Score is 8.8, indicating high severity.
Official resources
-
CVE-2026-60400 CVE record
CVE.org
-
CVE-2026-60400 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:42.497Z and has not been modified since then.