AI analysis
CVE-2026-60413 is a vulnerability in the Outside In Core component of Oracle Outside In Technology 8.5.8, Oracle's document parsing and conversion engine that is bundled within Oracle Fusion Middleware. An unauthenticated attacker who can log on to the infrastructure where Outside In Technology executes (CVSS attack vector AV:L, no privileges required) can trigger the flaw, and successful attacks require interaction from a user other than the attacker — consistent with a crafted file being submitted for parsing. The related ZDI advisory (ZDI-26-637) characterizes the issue as an integer overflow when parsing GEM files that can lead to remote code execution, while Oracle's entry maps the weakness to CWE-200 and rates it 7.8 (high) with high confidentiality, integrity, and availability impacts, resulting in takeover of Outside In Technology. Any deployment running the affected 8.5.8 release of Outside In Technology — typically embedded inside Oracle Fusion Middleware or other products that use the engine for document conversion — is affected. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so no exploitation is known.
What to do: Apply the fix for Outside In Technology 8.5.8 from Oracle's Critical Patch Update (Oracle lists 8.5.8 as the affected supported version; consult the Oracle advisory for the fixed release, as it is not stated in this data). Until patched, restrict interactive logon to hosts running Outside In Technology, limit automated parsing of untrusted documents (especially GEM files) to trusted sources, and monitor Oracle support channels for exploitation reports.
Affected
| Oracle Outside In Technology (Outside In Core, product of Oracle Fusion Middleware) | 8.5.8 (supported version listed as affected) |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).