Junglewise Threat Intelligence

CVE-2026-60406: Oracle TimesTen In-Memory Database compromise in Kubernetes Operator

CVE-2026-60406 · Severity: medium · CVSS 6.7 · Published 2026-07-21

Technologies: Oracle TimesTen In-Memory Database. Vendors: Oracle Corporation, Oracle.

Executive brief

A security vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, a high-performance database used for real-time applications. An attacker who already has high-level administrative access to the underlying server infrastructure could exploit this flaw to take full control of the database. This could lead to the unauthorized viewing, modification, or deletion of sensitive business data and disruption of database services.

Technical details

A vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0 allows for a complete compromise of the database instance. The flaw is categorized as easily exploitable but requires the attacker to have high-privileged local access (PR:H) to the infrastructure where the database is executing. Successful exploitation results in a total loss of confidentiality, integrity, and availability (C:H/I:H/A:H) for the affected database component. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation TimesTen In-Memory Database 26.1.1.1.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle and NVD publication.
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.

References

Related threats