Junglewise Threat Intelligence

CVE-2026-60410: Oracle TimesTen In-Memory Database partial DoS in Kubernetes Operator

CVE-2026-60410 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Technologies: Oracle TimesTen In-Memory Database. Vendors: Oracle.

Executive brief

A vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, a high-performance database used for real-time applications. An attacker with low-level access to the network can exploit this flaw to disrupt the database's availability. This could lead to a partial denial of service, potentially slowing down or interrupting business operations that rely on the database.

Technical details

A vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0 allows for a partial denial of service (DoS). The flaw is easily exploitable by a low-privileged attacker with network access via HTTPS. The attack does not require user interaction and has a low complexity, though it requires valid (low-level) credentials. Successful exploitation impacts the availability of the database service but does not compromise data confidentiality or integrity. Users should refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle TimesTen In-Memory Database 26.1.1.1.0

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References

Related threats