ZeroHour

CVE-2026-60392

Deserialization flaw in Oracle Outside In PDF Export SDK 8.5.8

CVSS 3.1
7.8 high
EPSS
<1%p22
Published
()
Modified
AI analysis

CVE-2026-60392 is a vulnerability in the Outside In PDF Export SDK component of Oracle Outside In Technology 8.5.8, which Oracle has tagged as deserialization of untrusted data (CWE-502); ZDI's advisory additionally characterizes it as an integer overflow while parsing PDF files that can lead to remote code execution. An unauthenticated attacker who has obtained logon access to the infrastructure where Outside In Technology runs must get a person other than themselves to interact with the system (user interaction required per the CVSS vector) for the local (AV:L) attack to succeed. A successful attack results in takeover of Outside In Technology with high confidentiality, integrity, and availability impact, reflected in the CVSS 3.1 base score of 7.8. Affected organizations are those running the 8.5.8 release of the PDF Export SDK, which Oracle ships within Fusion Middleware and licenses to third-party document-processing products. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Apply the fix for CVE-2026-60392 released in the corresponding Oracle Critical Patch Update; Oracle lists only version 8.5.8 of the PDF Export SDK as affected, so consult the CPU advisory for the fixed release and upgrade accordingly. Inventory which Fusion Middleware components and OEMed products embed Outside In on your hosts and restrict local logon to those systems to limit the attacker's ability to stage the required user interaction. Given the low EPSS (0.3%), absence of a public PoC, and user-assisted local vector, patch at your normal maintenance cadence rather than treating it as an emergency.

Affected
Oracle Outside In Technology (Outside In PDF Export SDK, Oracle Fusion Middleware)8.5.8
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Vendors
oracle
Products
outside in technology
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-60392, an integer overflow in Oracle Outside In PDF parsing enabling remote code execution, rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-635 describing an integer overflow vulnerability in PDF file parsing within Oracle Outside In Technology. Successful exploitation allows remote code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI assigned the flaw a CVSS rating of 7.8.