PatchSiren cyber security CVE debrief
CVE-2026-60408 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:43.390Z and has not been modified since then. The CVE-2026-60408 vulnerability affects Oracle TimesTen In-Memory Database version 26.1.1.1.0, allowing low-privileged attackers with network access via HTTPS to compromise the database, potentially leading to unauthorized read access to a subset of accessible data. System administrators and security professionals should review and apply Oracle's security patches, restrict network access, and monitor database activity. Evidence is based on official CVE and NVD records, and the CVSS score is 4.3, indicating a moderate level of risk.
- Vendor
- Oracle Corporation
- Product
- TimesTen In-Memory Database
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-31
Who should care
System administrators and security professionals responsible for Oracle TimesTen In-Memory Database installations should be aware of this vulnerability and take necessary steps to mitigate the risk. This includes reviewing and applying Oracle's security patches, restricting network access, and monitoring database activity.
Technical summary
The CVE-2026-60408 vulnerability is a medium-severity issue affecting Oracle TimesTen In-Memory Database version 26.1.1.1.0. It allows low-privileged attackers with network access via HTTPS to compromise the database, potentially leading to unauthorized read access to a subset of accessible data. The vulnerability is easily exploitable and has a CVSS score of 4.3, indicating a moderate level of risk. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). Successful attacks of this vulnerability can result in unauthorized read access to a subset of TimesTen In-Memory Database accessible data. System administrators and security professionals should review and apply Oracle's security patches, restrict network access, and monitor database activity to mitigate the risk.
Defensive priority
Medium priority given the CVSS score of 4.3 and the potential for unauthorized read access to TimesTen In-Memory Database accessible data.
Recommended defensive actions
- Review and apply Oracle's security patches for TimesTen In-Memory Database version 26.1.1.1.0.
- Restrict network access to TimesTen In-Memory Database to only necessary personnel.
- Monitor database access logs for suspicious activity.
- Implement compensating controls such as encryption and access controls.
- Verify inventory of TimesTen In-Memory Database installations and ensure they are up-to-date.
Evidence notes
The CVE-2026-60408 vulnerability affects Oracle TimesTen In-Memory Database version 26.1.1.1.0. The vulnerability allows a low-privileged attacker with network access via HTTPS to compromise TimesTen In-Memory Database, potentially leading to unauthorized read access to a subset of accessible data. Evidence is based on official CVE and NVD records.
Official resources
-
CVE-2026-60408 CVE record
CVE.org
-
CVE-2026-60408 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:43.390Z and has not been modified since then.