VDB

CVE-2026-60402

CVE-2026-60402 PUBLISHED CVSS 9.9 CRITICAL

Reported by oracle · Published July 21, 2026

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of TimesTen In-Memory Database. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Risk Scores

CVSS 3.1
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Oracle CorporationTimesTen In-Memory Database26.1.1.1.0
Oracle CorporationTimesTen In-Memory Database26.1.1.1.0, 26.1.1.1.0
oracletimesten_in-memory_database

Timeline

  • Jul 21, 2026 CVE Published
  • Jul 22, 2026 Coalition ESS Score
  • Jul 31, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›