ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 4 sources: “ZDI publishes four Oracle Outside In Technology file-parsing RCE advisories (CVSS 7.8) requiring user interaction” — merged summary and timeline →

ZDI-26-638: Oracle Outside In Technology WPS File Parsing Memory Corruption Remote Code Execution Vulnerability

mediumVulnerabilityimportance 22CVE-2026-60414
AI summary · glm-5.3-flash

ZDI disclosed memory corruption in Oracle Outside In Technology's WPS file parsing (CVE-2026-60414) enabling user-triggered remote code execution.

Zero Day Initiative published ZDI-26-638, a CVSS 7.8 memory corruption vulnerability in WPS file parsing within Oracle Outside In Technology. Remote attackers can execute arbitrary code on affected installations by convincing the target to visit a malicious page or open a malicious file, so user interaction is required. The issue is tracked as CVE-2026-60414. The advisory reports no exploitation.

  • Memory corruption in WPS file parsing, tracked as CVE-2026-60414
  • CVSS 7.8 remote code execution in Oracle Outside In Technology
  • User interaction required: opening a malicious file or page
  • Disclosed as ZDI-26-638; no in-the-wild exploitation reported

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-60414
Memory Corruption in WPS File Parsing in Oracle Outside In Technology 8.5.8

Oracle Outside In Technology (Outside In Core) version 8.5.8 contains a memory corruption flaw triggered while parsing WPS-format documents, per the Zero Day Initiative advisory. An unauthenticated attacker who has logon access to the infrastructure where the Outside In engine runs must get a person other than themselves to interact with the crafted file, at which point the parsing process is compromised. Successful exploitation results in takeover of Oracle Outside In Technology, with high confidentiality, integrity, and availability impact (CVSS 3.1 score 7.8, local attack vector with user interaction). Because Outside In is a document-conversion/preview engine embedded inside Oracle Fusion Middleware and other products, anyone running an affected deployment that processes untrusted WPS documents is exposed. There is currently no public proof of concept, no listing in CISA's KEV, and a low 0.2% EPSS probability of exploitation within 30 days, indicating no known exploitation activity.

Do: Upgrade Outside In Technology 8.5.8 to the patched release distributed through the Oracle Critical Patch Update that addresses CVE-2026-60414, and identify which Oracle Fusion Middleware (or third-party) products bundle Outside In so they are patched together. Until patched, restrict or inspect untrusted WPS files before they reach the Outside In conversion engine and limit local logon access to the systems where it runs. Monitor Oracle's advisory for the fixed version applicable to your product bundles, since Outside In is typically consumed as an embedded component rather than patched directly.

7.8<1%
  • Oracle Outside In Technology (Outside In Core component), part of Oracle Fusion Middleware 8.5.8
nicheunknown; plausibly tens of thousands of enterprise deployments, as Outside In is an embedded SDK rather than a standalone internet-facing service
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60414.

This source does not provide full text. Read it at zerodayinitiative.com.