Junglewise Threat Intelligence

CVE-2026-60403: Oracle TimesTen In-Memory Database denial of service in Kubernetes Operator

CVE-2026-60403 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle TimesTen In-Memory Database. Vendors: Oracle.

Executive brief

A vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, a high-performance database used for real-time applications. An attacker with low-level access to the network can exploit this flaw to cause the database to hang or crash repeatedly. This results in a complete denial of service, disrupting business operations and application availability.

Technical details

A vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database (version 26.1.1.1.0) allows for a denial of service (DoS). The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Successful exploitation enables the attacker to cause a hang or a frequently repeatable crash of the database instance. The vulnerability is tracked as CVE-2026-60403 with a CVSS 3.1 base score of 6.5, specifically impacting system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.

Affected products

  • Oracle TimesTen In-Memory Database 26.1.1.1.0

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published.

References

Related threats