ZeroHour

CVE-2026-60412

large

PostScript Parsing Heap Overflow in Oracle Outside In Technology 8.5.8

CVSS 3.1
7.8 high
EPSS
<1%p22
Published
()
Modified
AI analysis

CVE-2026-60412 is a flaw in the Outside In Core component of Oracle Outside In Technology 8.5.8, a document-parsing engine distributed as part of Oracle Fusion Middleware; the CVE is classified as CWE-502 (deserialization of untrusted data), while the related ZDI advisory (ZDI-26-636) describes it as a heap-based buffer overflow triggered when parsing PostScript files. The attack vector is local (AV:L): an unauthenticated attacker must have logon to the infrastructure where Outside In executes, and successful exploitation additionally requires human interaction from someone other than the attacker, typically a user or service processing an attacker-supplied file. A successful attack can result in takeover of the Outside In Technology instance with high confidentiality, integrity and availability impact (CVSS 3.1 7.8), and the ZDI advisory characterizes the outcome as remote code execution. The affected version in Oracle's advisory is 8.5.8, so organizations running this release directly or bundled inside Oracle Fusion Middleware products are in scope. Exploitation has not been observed: there is no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (22nd percentile).

What to do: Apply the Outside In Technology fix from the Oracle Critical Patch Update covering this CVE, upgrading 8.5.8 to the patched release Oracle identifies and updating any Fusion Middleware products that bundle the engine. Until patched, restrict which accounts can perform Outside In document conversions and limit processing of untrusted PostScript and similar files, since exploitation requires local logon plus user interaction. No public PoC or in-the-wild exploitation is known, but monitor Oracle support notes for the exact patched version and dependent product updates.

Affected
Oracle Outside In Technology (Outside In Core, Oracle Fusion Middleware)8.5.8
Estimated exposure
large≈ tens of thousands of Oracle middleware/document-processing deployments (estimated; no public install counts) — Outside In 8.5.8 is an embedded document-conversion engine inside widely deployed Oracle Fusion Middleware products (e.g., WebCenter Content and similar content/search components), and typical enterprise deployment patterns suggest on the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Vendors
oracle
Products
outside in technology
Weakness
CWE-502
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI disclosed a heap-based buffer overflow in Oracle Outside In Technology's PostScript parsing (CVE-2026-60412) enabling user-triggered remote code execution.

Zero Day Initiative published ZDI-26-636, a CVSS 7.8 heap-based buffer overflow in PostScript file parsing within Oracle Outside In Technology. Remote attackers can execute arbitrary code when the target opens a malicious file or visits a malicious page, making user interaction a requirement. The vulnerability is tracked as CVE-2026-60412. The advisory reports no exploitation.