ZDI-26-637: Oracle Outside In Technology GEM File Parsing Integer Overflow Remote Code Execution Vulnerability
ZDI disclosed an integer overflow in Oracle Outside In Technology's GEM file parsing (CVE-2026-60413) enabling user-triggered remote code execution.
Zero Day Initiative published ZDI-26-637, a CVSS 7.8 integer overflow in GEM file parsing within Oracle Outside In Technology. Exploitation requires user interaction, such as opening a malicious file or visiting a malicious page, and results in arbitrary code execution on affected installations. The flaw is tracked as CVE-2026-60413. No exploitation activity is reported.
- Integer overflow in GEM file parsing, tracked as CVE-2026-60413
- CVSS 7.8 remote code execution in Oracle Outside In Technology
- Requires user interaction with a malicious file or page
- Disclosed as ZDI-26-637; no exploitation reported
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-60413 | Oracle Outside In Technology GEM File Parsing Integer Overflow Allows Takeover CVE-2026-60413 is a vulnerability in the Outside In Core component of Oracle Outside In Technology 8.5.8, Oracle's document parsing and conversion engine that is bundled within Oracle Fusion Middleware. An unauthenticated attacker who can log on to the infrastructure where Outside In Technology executes (CVSS attack vector AV:L, no privileges required) can trigger the flaw, and successful attacks require interaction from a user other than the attacker — consistent with a crafted file being submitted for parsing. The related ZDI advisory (ZDI-26-637) characterizes the issue as an integer overflow when parsing GEM files that can lead to remote code execution, while Oracle's entry maps the weakness to CWE-200 and rates it 7.8 (high) with high confidentiality, integrity, and availability impacts, resulting in takeover of Outside In Technology. Any deployment running the affected 8.5.8 release of Outside In Technology — typically embedded inside Oracle Fusion Middleware or other products that use the engine for document conversion — is affected. There is currently no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days, so no exploitation is known. Do: Apply the fix for Outside In Technology 8.5.8 from Oracle's Critical Patch Update (Oracle lists 8.5.8 as the affected supported version; consult the Oracle advisory for the fixed release, as it is not stated in this data). Until patched, restrict interactive logon to hosts running Outside In Technology, limit automated parsing of untrusted documents (especially GEM files) to trusted sources, and monitor Oracle support channels for exploitation reports. | 7.8 | <1% |
| — |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60413.
This source does not provide full text. Read it at zerodayinitiative.com.