PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60404 Oracle Corporation CVE debrief

The CVE-2026-60404 vulnerability is in the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. This vulnerability allows a low-privileged attacker with network access via HTTPS to compromise the database, potentially causing a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. The CVSS 3.1 Base Score is 6.5, indicating a medium severity. The vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. Organizations should review and apply patches or updates provided by Oracle, implement compensating controls, and monitor for potential attacks. The CVE record was published on 2026-07-21T22:17:42.943Z and has not been modified since then. The vulnerability affects Oracle TimesTen In-Memory Database version 26.1.1.1.0.

Vendor
Oracle Corporation
Product
TimesTen In-Memory Database
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-31
Advisory published
2026-07-21
Advisory updated
2026-07-31

Who should care

Organizations using Oracle TimesTen In-Memory Database version 26.1.1.1.0 should be aware of this vulnerability and take necessary actions to remediate it. This includes reviewing and applying patches or updates provided by Oracle, implementing compensating controls, and monitoring for potential attacks. Operators and security teams responsible for managing and securing TimesTen In-Memory Database deployments should prioritize this vulnerability due to its potential impact on availability.

Technical summary

The CVE-2026-60404 vulnerability is in the Kubernetes Operator component of Oracle TimesTen In-Memory Database version 26.1.1.1.0. A low-privileged attacker with network access via HTTPS can exploit this vulnerability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database. The CVSS 3.1 Base Score is 6.5 (Availability impacts), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The vulnerability allows unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.

Defensive priority

Medium priority given the CVSS score of 6.5 and the potential for a hang or frequently repeatable crash (complete DOS) of TimesTen In-Memory Database.

Recommended defensive actions

  • Inventory and verify the version of TimesTen In-Memory Database to check for vulnerability
  • Apply patches or updates provided by Oracle to remediate the vulnerability
  • Implement compensating controls such as monitoring and exception tracking
  • Restrict network access to the database to minimize the attack surface
  • Review and update security configurations to prevent similar vulnerabilities
  • Monitor relevant logs and detection systems for exposed assets
  • Track exceptions and retest remediated assets

Evidence notes

The CVE-2026-60404 vulnerability affects Oracle TimesTen In-Memory Database version 26.1.1.1.0. It allows a low-privileged attacker with network access via HTTPS to compromise the database, potentially causing a hang or crash. The CVSS 3.1 Base Score is 6.5, indicating a medium severity. The vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:42.943Z and has not been modified since then.