Description
Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of TimesTen In-Memory Database accessible data as well as unauthorized read access to a subset of TimesTen In-Memory Database accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 5.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).
Published: 2026-07-21
Score: 5.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is in the Kubernetes Operator of Oracle TimesTen In‑Memory Database. A high‑privileged local attacker who can log on to the infrastructure where the database runs may gain unauthorized access to the database. The attacker can then create, update, delete, or read data, and can cause a partial denial of service.

Affected Systems

Oracle TimesTen In‑Memory Database version 26.1.1.1.0 is impacted. No other products are explicitly listed as affected, but an attack on this component could potentially alter the state of additional products that rely on the database.

Risk and Exploitability

The CVSS base score of 5.7 indicates moderate severity, while the EPSS score of < 1 % signals a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog and requires a local attacker with high privileges and no user interaction. Because the attack scope changes, the attacker can gain partial control over the database, allowing unauthorized modifications, reads, and limited denial of service.

Generated by OpenCVE AI on August 2, 2026 at 22:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle TimesTen to the latest release that includes the fix for the 26.1.1.1.0 issue
  • Limit local access to the TimesTen infrastructure to verified users and enforce least‑privilege permissions
  • Apply role‑based access control within the database to restrict read and write privileges to authorized roles
  • Monitor for anomalous database activity and use audit logging to detect unauthorized changes

Generated by OpenCVE AI on August 2, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title High Privilege Data Modification via TimesTen Kubernetes Operator

Sat, 01 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title High Privilege Data Modification via TimesTen Kubernetes Operator

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Data Manipulation in Oracle TimesTen In-Memory Database via Kubernetes Operator

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Data Manipulation in Oracle TimesTen In-Memory Database via Kubernetes Operator

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of TimesTen In-Memory Database accessible data as well as unauthorized read access to a subset of TimesTen In-Memory Database accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 5.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).
First Time appeared Oracle
Oracle timesten In-memory Database
CPEs cpe:2.3:a:oracle:timesten_in-memory_database:26.1.1.1.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle timesten In-memory Database
References
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L'}


Subscriptions

Oracle Timesten In-memory Database
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:10:13.125Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60409

cve-icon Vulnrichment

Updated: 2026-07-24T16:10:00.982Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses