ZeroHour

CVE-2026-60414

niche

Memory Corruption in WPS File Parsing in Oracle Outside In Technology 8.5.8

CVSS 3.1
7.8 high
EPSS
<1%p8
Published
()
Modified
AI analysis

Oracle Outside In Technology (Outside In Core) version 8.5.8 contains a memory corruption flaw triggered while parsing WPS-format documents, per the Zero Day Initiative advisory. An unauthenticated attacker who has logon access to the infrastructure where the Outside In engine runs must get a person other than themselves to interact with the crafted file, at which point the parsing process is compromised. Successful exploitation results in takeover of Oracle Outside In Technology, with high confidentiality, integrity, and availability impact (CVSS 3.1 score 7.8, local attack vector with user interaction). Because Outside In is a document-conversion/preview engine embedded inside Oracle Fusion Middleware and other products, anyone running an affected deployment that processes untrusted WPS documents is exposed. There is currently no public proof of concept, no listing in CISA's KEV, and a low 0.2% EPSS probability of exploitation within 30 days, indicating no known exploitation activity.

What to do: Upgrade Outside In Technology 8.5.8 to the patched release distributed through the Oracle Critical Patch Update that addresses CVE-2026-60414, and identify which Oracle Fusion Middleware (or third-party) products bundle Outside In so they are patched together. Until patched, restrict or inspect untrusted WPS files before they reach the Outside In conversion engine and limit local logon access to the systems where it runs. Monitor Oracle's advisory for the fixed version applicable to your product bundles, since Outside In is typically consumed as an embedded component rather than patched directly.

Affected
Oracle Outside In Technology (Outside In Core component), part of Oracle Fusion Middleware8.5.8
Estimated exposure
nicheunknown; plausibly tens of thousands of enterprise deployments, as Outside In is an embedded SDK rather than a standalone internet-facing service — No public install counters or internet-wide scans exist for this embedded document-parsing library, so the estimate is based on its deployment pattern as a bundled component within Oracle Fusion Middleware and other enterprise…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Vendors
oracle
Products
outside in technology
Weakness
CWE-200
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability

ZDI disclosed memory corruption in Oracle Outside In Technology's WPS file parsing (CVE-2026-60414) enabling user-triggered remote code execution.

Zero Day Initiative published ZDI-26-638, a CVSS 7.8 memory corruption vulnerability in WPS file parsing within Oracle Outside In Technology. Remote attackers can execute arbitrary code on affected installations by convincing the target to visit a malicious page or open a malicious file, so user interaction is required. The issue is tracked as CVE-2026-60414. The advisory reports no exploitation.