Oracle's July 2026 Critical Patch Update discloses CVE-2026-60402, a CVSS 9.9 vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database that allows a low-privileged attacker to fully take over the database over the network.
What Is It
CVE-2026-60402 is a critical vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database. Oracle describes it as easily exploitable: a low-privileged attacker with network access via HTTPS can compromise the database. Because the flaw carries a scope change, successful attacks may significantly impact additional products beyond TimesTen itself. A successful attack can result in complete takeover of the TimesTen In-Memory Database.
Why It Matters
The vulnerability holds a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That combination, network attack vector, low attack complexity, only low privileges required, and no user interaction, makes it straightforward to exploit remotely. The impact is high across all three dimensions: confidentiality, integrity, and availability. The changed scope means the blast radius can extend past the database to other components in the environment.
What's Vulnerable
The affected product is Oracle TimesTen In-Memory Database, specifically the Kubernetes Operator component. The supported version identified as affected is 26.1.1.1.0.
Patch Status
Oracle addresses this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators running the affected TimesTen version should apply the fixes from that update. This CVE does not currently appear in the CISA Known Exploited Vulnerabilities catalog, and no confirmation of active exploitation was provided in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory; July 2026: https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60402: https://nvd.nist.gov/vuln/detail/CVE-2026-60402