Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker with network access via HTTPS can exploit a flaw in the Oracle TimesTen In‑Memory Database Kubernetes Operator, enabling full control of the database. The vulnerability permits the attacker to compromise confidentiality, integrity, and availability, effectively resulting in a takeover of the database as detailed in the official advisory.

Affected Systems

The affected product is Oracle TimesTen In‑Memory Database version 26.1.1.1.0. The description notes that successful attacks may also have scope changes that could impact additional products within the environment.

Risk and Exploitability

The CVSS 3.1 base score of 9.9 indicates critical severity, and the EPSS score of less than 1% suggests that, although the vulnerability is technically easy to exploit, its current exploitation probability is low. The issue is not listed in CISA’s KEV catalog. Attackers would need only low privilege and network access to the HTTPS endpoint of the Kubernetes Operator, which may also influence the broader environment due to the scope change noted in the vulnerability description.

Generated by OpenCVE AI on August 2, 2026 at 22:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s security patch for TimesTen 26.1.1.1.0 or upgrade to a newer, unaffected release.
  • If the Kubernetes Operator is not required for your deployment, disable or remove it to eliminate the attack surface.
  • Restrict HTTPS access to the TimesTen instance by configuring firewall rules or network policies to allow only trusted IP ranges.

Generated by OpenCVE AI on August 2, 2026 at 22:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title TimesTen In-Memory Database Kubernetes Operator Vulnerability Allows Remote Database Takeover

Thu, 30 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title TimesTen In-Memory Database Kubernetes Operator Vulnerability Allows Remote Database Takeover

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via HTTPS in Oracle TimesTen Kubernetes Operator Allows Database Takeover
Weaknesses CWE-287

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via HTTPS in Oracle TimesTen Kubernetes Operator Allows Database Takeover
Weaknesses CWE-287

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:22:11.276Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60402

cve-icon Vulnrichment

Updated: 2026-07-24T16:21:59.365Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:45:17Z

Weaknesses