Vulnerability in Oracle TimesTen In-Memory Database affecting Kubernetes Operator
CVE-2026-60409

5.7MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60409?

A vulnerability exists in the TimesTen In-Memory Database product's Kubernetes Operator that allows a high-privileged attacker to exploit the database when logged into the infrastructure where it operates. This vulnerability can lead to unauthorized updates, inserts, or deletions of data within the database. Additionally, it provides unauthorized read access to certain datasets and may enable an attacker to initiate a partial denial of service, affecting availability. It poses risks not only to TimesTen In-Memory Database itself but potentially extends to other connected products.

Affected Version(s)

TimesTen In-Memory Database 26.1.1.1.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.