Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low privileged attacker who is able to log into the infrastructure where the TimesTen In‑Memory Database runs can use a difficult‑to‑exploit flaw in the Kubernetes Operator component to compromise the database. Successful exploitation lets the attacker read or modify data stored in TimesTen, without affecting the integrity or availability of the service it permits unauthorized access to critical data. The vulnerability is a CWE‑284 (Access Control Failure).

Affected Systems

Oracle TimesTen In-Memory Database, version 26.1.1.1.0. The flaw applies only to this specific release and to the Kubernetes Operator that manages it.

Risk and Exploitability

The CVSS v3.1 score is 5.6, indicating moderate risk with a local attacker who has low privileges and no user interaction required. The EPSS score of < 1% suggests that exploitation is unlikely but not impossible, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to log on to the host environment and exploit the Operator component; the success of the attack can lead to unauthorized data access across all TimesTen instances in scope.

Generated by OpenCVE AI on August 4, 2026 at 03:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch for Oracle TimesTen In‑Memory Database 26.1.1.1.0 as provided in Oracle CPU July 2026.
  • Restrict local logon privileges on hosts that run the TimesTen database to only trusted administrators.
  • Implement network segmentation so that only authorized services can communicate with the TimesTen instances.

Generated by OpenCVE AI on August 4, 2026 at 03:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Kubernetes Operator Vulnerability in Oracle TimesTen Enables Unauthorized Data Access

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Low‑privilege logon enables unauthorized data access in Oracle TimesTen In‑Memory Database
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Low‑privilege logon enables unauthorized data access in Oracle TimesTen In‑Memory Database
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:16:20.911Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60407

cve-icon Vulnrichment

Updated: 2026-07-24T16:15:56.682Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:00:03Z

Weaknesses