Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Kubernetes Operator component of Oracle TimesTen In-Memory Database, allowing a locally privileged attacker with infrastructure logon to abuse improper access control and privilege management. The flaw permits the attacker to read any data stored in the database, effectively bypassing normal authorization checks and potentially gaining full visibility of all TimesTen data. The CVSS v3.1 Base Score of 6.5 highlights a moderate severity with a focus on confidentiality impact.

Affected Systems

Oracle TimesTen In-Memory Database version 26.1.1.1.0 is affected. Systems running this exact release, specifically the Kubernetes Operator that manages database instances, are vulnerable. No other product versions are listed as impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, combining a local attack vector (AV:L), low attack complexity (AC:L), low privileges required (PR:L), and no user interaction (UI:N). The EPSS score of less than 1% suggests a low but non-zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation yet. However, because the flaw changes scope (S:C) and can expose all critical data, it poses a significant risk to systems where the affected release is deployed.

Generated by OpenCVE AI on August 4, 2026 at 04:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle TimesTen In-Memory Database to a release that contains the fix for the Kubernetes Operator vulnerability.
  • Limit local administrator access to trusted personnel and enforce least privilege for any user who can log on to the infrastructure hosting the database.
  • Monitor Kubernetes cluster logs and operator API calls for anomalous read attempts and implement alerting for unauthorized data access attempts.

Generated by OpenCVE AI on August 4, 2026 at 04:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title TimesTen In-Memory Database Kubernetes Operator Vulnerability Allows Local Privilege Escalation

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title TimesTen In-Memory Database Kubernetes Operator Vulnerability Allows Local Privilege Escalation

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle TimesTen In-Memory Database Enables Unauthorized Data Access
Weaknesses CWE-285

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle TimesTen In-Memory Database Enables Unauthorized Data Access
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:23:02.553Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60401

cve-icon Vulnrichment

Updated: 2026-07-24T16:22:46.784Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:15:03Z

Weaknesses