Executive brief
A vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database allows a user with low-level access to the underlying infrastructure to gain unauthorized access to sensitive information. This could lead to the exposure of critical business data stored within the database or impact other connected systems. The issue affects organizations using the specific database version managed within Kubernetes environments.
Technical details
A vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database (version 26.1.1.1.0) allows for unauthorized data access. The flaw is categorized by a CVSS 3.1 score of 6.5, specifically noting a 'Scope Change' (S:C), which implies that an exploit can impact components beyond the database itself. An attacker with low-privileged local access to the infrastructure where the database executes can exploit this vulnerability to achieve high confidentiality impact (C:H). No user interaction is required for exploitation. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle TimesTen In-Memory Database 26.1.1.1.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published.