Junglewise Threat Intelligence

CVE-2026-60402: Oracle TimesTen In-Memory Database compromise in Kubernetes Operator

CVE-2026-60402 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Technologies: Oracle TimesTen In-Memory Database. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, a high-performance database used for real-time applications. An attacker with low-level access to the network can exploit this flaw to take full control of the database system. Because this component manages database deployments within a cloud environment, a successful attack could also compromise other connected systems and services, leading to significant data loss or operational disruption.

Technical details

This vulnerability affects the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTPS. The flaw is notable for a 'scope change' (CVSS S:C), meaning a successful exploit allows the attacker to move beyond the database's security boundaries to impact the underlying Kubernetes environment or other integrated products. Successful exploitation results in a complete loss of confidentiality, integrity, and availability (takeover of the database). Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle TimesTen In-Memory Database 26.1.1.1.0

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats