Junglewise Threat Intelligence

CVE-2026-60404: Oracle TimesTen In-Memory Database denial of service in Kubernetes Operator

CVE-2026-60404 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle TimesTen In-Memory Database. Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, a high-performance database used for real-time applications. An attacker with basic user access can remotely trigger a system hang or a repeated crash, leading to a complete service outage. This disruption can halt business operations that rely on the database for immediate data processing.

Technical details

A vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database (version 26.1.1.1.0) allows for a Denial of Service (DoS). The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. Successful exploitation enables the attacker to cause a frequently repeatable crash or a system hang, resulting in a complete loss of availability for the database service. The vulnerability is tracked as CVE-2026-60404 and was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation TimesTen In-Memory Database 26.1.1.1.0

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
  • 2026-07-21: disclosed: CVE-2026-60404 was published to the NVD.

References

Related threats