SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60402 2026-07-21

CVE-2026-60402: Critical Takeover Flaw in Oracle TimesTen In-Memory Database

"Oracle's July 2026 Critical Patch Update discloses CVE-2026-60402, a CVSS 9.9 vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database that allows a low-privileged attacker to fully take…"

Oracle's July 2026 Critical Patch Update discloses CVE-2026-60402, a CVSS 9.9 vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database that allows a low-privileged attacker to fully take over the database over the network.

What Is It

CVE-2026-60402 is a critical vulnerability in the Kubernetes Operator component of Oracle TimesTen In-Memory Database. Oracle describes it as easily exploitable: a low-privileged attacker with network access via HTTPS can compromise the database. Because the flaw carries a scope change, successful attacks may significantly impact additional products beyond TimesTen itself. A successful attack can result in complete takeover of the TimesTen In-Memory Database.

Why It Matters

The vulnerability holds a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That combination, network attack vector, low attack complexity, only low privileges required, and no user interaction, makes it straightforward to exploit remotely. The impact is high across all three dimensions: confidentiality, integrity, and availability. The changed scope means the blast radius can extend past the database to other components in the environment.

What's Vulnerable

The affected product is Oracle TimesTen In-Memory Database, specifically the Kubernetes Operator component. The supported version identified as affected is 26.1.1.1.0.

Patch Status

Oracle addresses this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators running the affected TimesTen version should apply the fixes from that update. This CVE does not currently appear in the CISA Known Exploited Vulnerabilities catalog, and no confirmation of active exploitation was provided in the supplied source material.

Sources