ZeroHour

CVE-2026-60413

Oracle Outside In Technology GEM File Parsing Integer Overflow Allows Takeover

CVSS 3.1
7.8 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-60413 is a vulnerability in the Outside In Core component of Oracle Outside In Technology 8.5.8, Oracle's document parsing and conversion engine that is bundled within Oracle Fusion Middleware. An unauthenticated attacker who can log on to the infrastructure where Outside In Technology executes (CVSS attack vector AV:L, no privileges required) can trigger the flaw, and successful attacks require interaction from a user other than the attacker — consistent with a crafted file being submitted for parsing. The related ZDI advisory (ZDI-26-637) characterizes the issue as an integer overflow when parsing GEM files that can lead to remote code execution, while Oracle's entry maps the weakness to CWE-200 and rates it 7.8 (high) with high confidentiality, integrity, and availability impacts, resulting in takeover of Outside In Technology. Any deployment running the affected 8.5.8 release of Outside In Technology — typically embedded inside Oracle Fusion Middleware or other products that use the engine for document conversion — is affected. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so no exploitation is known.

What to do: Apply the fix for Outside In Technology 8.5.8 from Oracle's Critical Patch Update (Oracle lists 8.5.8 as the affected supported version; consult the Oracle advisory for the fixed release, as it is not stated in this data). Until patched, restrict interactive logon to hosts running Outside In Technology, limit automated parsing of untrusted documents (especially GEM files) to trusted sources, and monitor Oracle support channels for exploitation reports.

Affected
Oracle Outside In Technology (Outside In Core, product of Oracle Fusion Middleware)8.5.8 (supported version listed as affected)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Vendors
oracle
Products
outside in technology
Weakness
CWE-200
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-637: Oracle Outside In Technology GEM File Parsing Integer Overflow Remote Code Execution Vulnerability

ZDI disclosed an integer overflow in Oracle Outside In Technology's GEM file parsing (CVE-2026-60413) enabling user-triggered remote code execution.

Zero Day Initiative published ZDI-26-637, a CVSS 7.8 integer overflow in GEM file parsing within Oracle Outside In Technology. Exploitation requires user interaction, such as opening a malicious file or visiting a malicious page, and results in arbitrary code execution on affected installations. The flaw is tracked as CVE-2026-60413. No exploitation activity is reported.