AI analysis
CVE-2026-60392 is a vulnerability in the Outside In PDF Export SDK component of Oracle Outside In Technology 8.5.8, which Oracle has tagged as deserialization of untrusted data (CWE-502); ZDI's advisory additionally characterizes it as an integer overflow while parsing PDF files that can lead to remote code execution. An unauthenticated attacker who has obtained logon access to the infrastructure where Outside In Technology runs must get a person other than themselves to interact with the system (user interaction required per the CVSS vector) for the local (AV:L) attack to succeed. A successful attack results in takeover of Outside In Technology with high confidentiality, integrity, and availability impact, reflected in the CVSS 3.1 base score of 7.8. Affected organizations are those running the 8.5.8 release of the PDF Export SDK, which Oracle ships within Fusion Middleware and licenses to third-party document-processing products. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
What to do: Apply the fix for CVE-2026-60392 released in the corresponding Oracle Critical Patch Update; Oracle lists only version 8.5.8 of the PDF Export SDK as affected, so consult the CPU advisory for the fixed release and upgrade accordingly. Inventory which Fusion Middleware components and OEMed products embed Outside In on your hosts and restrict local logon to those systems to limit the attacker's ability to stage the required user interaction. Given the low EPSS (0.3%), absence of a public PoC, and user-assisted local vector, patch at your normal maintenance cadence rather than treating it as an emergency.
Affected
| Oracle Outside In Technology (Outside In PDF Export SDK, Oracle Fusion Middleware) | 8.5.8 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).