PatchSiren cyber security CVE debrief
CVE-2026-60404 Oracle Corporation CVE debrief
The CVE-2026-60404 vulnerability is in the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. This vulnerability allows a low-privileged attacker with network access via HTTPS to compromise the database, potentially causing a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. The CVSS 3.1 Base Score is 6.5, indicating a medium severity. The vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. Organizations should review and apply patches or updates provided by Oracle, implement compensating controls, and monitor for potential attacks. The CVE record was published on 2026-07-21T22:17:42.943Z and has not been modified since then. The vulnerability affects Oracle TimesTen In-Memory Database version 26.1.1.1.0.
- Vendor
- Oracle Corporation
- Product
- TimesTen In-Memory Database
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-31
Who should care
Organizations using Oracle TimesTen In-Memory Database version 26.1.1.1.0 should be aware of this vulnerability and take necessary actions to remediate it. This includes reviewing and applying patches or updates provided by Oracle, implementing compensating controls, and monitoring for potential attacks. Operators and security teams responsible for managing and securing TimesTen In-Memory Database deployments should prioritize this vulnerability due to its potential impact on availability.
Technical summary
The CVE-2026-60404 vulnerability is in the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. A low-privileged attacker with network access via HTTPS can exploit this vulnerability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. The CVSS 3.1 Base Score is 6.5 (Availability impacts), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability allows unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.
Defensive priority
Medium priority given the CVSS score of 6.5 and the potential for a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.
Recommended defensive actions
- Inventory and verify the version of TimesTen In-Memory Database to check for vulnerability
- Apply patches or updates provided by Oracle to remediate the vulnerability
- Implement compensating controls such as monitoring and exception tracking
- Restrict network access to the database to minimize the attack surface
- Review and update security configurations to prevent similar vulnerabilities
- Monitor relevant logs and detection systems for exposed assets
- Track exceptions and retest remediated assets
Evidence notes
The CVE-2026-60404 vulnerability affects Oracle TimesTen In-Memory Database version 26.1.1.1.0. It allows a low-privileged attacker with network access via HTTPS to compromise the database, potentially causing a hang or crash. The CVSS 3.1 Base Score is 6.5, indicating a medium severity. The vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.
Official resources
-
CVE-2026-60404 CVE record
CVE.org
-
CVE-2026-60404 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:42.943Z and has not been modified since then.