Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The TimesTen In‑Memory Database Kubernetes Operator contains a privilege escalation weakness (CWE‑269) that allows a logged‑on, high‑privileged user on the host to take full control of the database system. This local win elevates the attacker’s authority to compromise Confidentiality, Integrity, and Availability of the data stored in the database.

Affected Systems

All Oracle TimesTen In‑Memory Database installations running version 26.1.1.1.0 that are deployed with the Kubernetes Operator in any supported environment.

Risk and Exploitability

The CVSS 3.1 base score of 6.7 indicates a moderate severity. The EPSS score of less than 1% shows that exploitation attempts are currently sparse, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an attacker with local high‑privilege access to the host where TimesTen runs; no network connectivity or user interaction is needed. The attack surface is therefore limited to compromised or otherwise accessible pods or hosts that can run the Operator.

Generated by OpenCVE AI on August 4, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a non‑affected release of TimesTen In‑Memory Database.
  • Restrict access to the Kubernetes cluster and the host machines, enforcing least‑privilege for users who can log in and manage the Operator.
  • Segment the network to isolate database nodes and deploy monitoring to detect anomalous database activity.

Generated by OpenCVE AI on August 4, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in TimesTen In-Memory Database Kubernetes Operator

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:17:32.835Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60406

cve-icon Vulnrichment

Updated: 2026-07-24T16:17:14.555Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management