Vulnerability in Oracle TimesTen In-Memory Database Kubernetes Operator
CVE-2026-60402

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60402?

An identified vulnerability in the Kubernetes Operator of Oracle's TimesTen In-Memory Database could allow an attacker with low-level access to the network through HTTPS to compromise the database system. This flaw in version 26.1.1.1.0 can lead to unauthorized access, potentially impacting the confidentiality, integrity, and availability of the database. Due to the nature of the vulnerability, a successful exploit could result in the complete takeover of the affected TimesTen installation, thereby posing a significant risk to applications that rely on this database for critical data processing.

Affected Version(s)

TimesTen In-Memory Database 26.1.1.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.