SEPTEMBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-60409

MEDIUM · CVSS 5.7 EPSS 0.12% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The vulnerability affects the TimesTen In-Memory Database within Oracle's Kubernetes Operator, specifically version 26.1.1.1.0, allowing high-privileged attackers with access to the infrastructure to compromise the database. Successful exploitation can lead to unauthorized data manipulation, including updates, inserts, and deletions, as well as unauthorized read access and potential partial denial of service. Organizations using this version of Oracle TimesTen should prioritize remediation to mitigate risks to data integrity and availability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-60409
Severity
MEDIUM
CVSS
5.7
EPSS
0.12%
Oracle Kubernetes

Original NVD Description

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Operator). The supported version that is affected is 26.1.1.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where TimesTen In-Memory Database executes to compromise TimesTen In-Memory Database. While the vulnerability is in TimesTen In-Memory Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of TimesTen In-Memory Database accessible data as well as unauthorized read access to a subset of TimesTen In-Memory Database accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of TimesTen In-Memory Database. CVSS 3.1 Base Score 5.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L).

Related CVEs

Other vulnerabilities affecting the same vendor(s)