PatchSiren cyber security CVE debrief
CVE-2026-60409 Oracle Corporation CVE debrief
The CVE-2026-60409 vulnerability is a security issue in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. This vulnerability allows high privileged attackers with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. Successful attacks can result in unauthorized update, insert or delete access to some of TimesTen In-Memory Database accessible data as well as unauthorized read access to a subset of TimesTen In-Memory Database accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. Oracle TimesTen In-Memory Database customers, administrators, and users who have high privileges on the infrastructure where TimesTen In-Memory Database executes should be aware of this vulnerability and take necessary actions to mitigate it.
- Vendor
- Oracle Corporation
- Product
- TimesTen In-Memory Database
- CVSS
- MEDIUM 5.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-31
Who should care
Oracle TimesTen In-Memory Database customers, administrators, and users who have high privileges on the infrastructure where TimesTen In-Memory Database executes should be aware of this vulnerability and take necessary actions to mitigate it.
Technical summary
The CVE-2026-60409 vulnerability is in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. The vulnerability allows high privileged attackers with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. Successful attacks can result in unauthorized update, insert or delete access to some of TimesTen In-Memory Database accessible data as well as unauthorized read access to a subset of TimesTen In-Memory Database accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database.
Defensive priority
Oracle TimesTen In-Memory Database customers should prioritize patching this vulnerability, as it allows high-privileged attackers to compromise the database and impact additional products.
Recommended defensive actions
- Apply the patch from Oracle as soon as possible
- Review and update access controls to limit logon to infrastructure where TimesTen In-Memory Database executes
- Monitor TimesTen In-Memory Database for unauthorized updates, inserts, or deletes
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE description indicates a vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change).
Official resources
-
CVE-2026-60409 CVE record
CVE.org
-
CVE-2026-60409 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:43.503Z and has not been modified since then.