ZeroHour
ZDI Published Advisoriespublished ()ingested 1
Part of a story covered by 4 sources: “ZDI publishes four Oracle Outside In Technology file-parsing RCE advisories (CVSS 7.8) requiring user interaction” — merged summary and timeline →

ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability

mediumAdvisoryimportance 25CVE-2026-60392
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-60392, an integer overflow in Oracle Outside In PDF parsing enabling remote code execution, rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-635 describing an integer overflow vulnerability in PDF file parsing within Oracle Outside In Technology. Successful exploitation allows remote code execution but requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI assigned the flaw a CVSS rating of 7.8.

  • Exploitation requires user interaction with a malicious file or page.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-60392
Deserialization flaw in Oracle Outside In PDF Export SDK 8.5.8

CVE-2026-60392 is a vulnerability in the Outside In PDF Export SDK component of Oracle Outside In Technology 8.5.8, which Oracle has tagged as deserialization of untrusted data (CWE-502); ZDI's advisory additionally characterizes it as an integer overflow while parsing PDF files that can lead to remote code execution. An unauthenticated attacker who has obtained logon access to the infrastructure where Outside In Technology runs must get a person other than themselves to interact with the system (user interaction required per the CVSS vector) for the local (AV:L) attack to succeed. A successful attack results in takeover of Outside In Technology with high confidentiality, integrity, and availability impact, reflected in the CVSS 3.1 base score of 7.8. Affected organizations are those running the 8.5.8 release of the PDF Export SDK, which Oracle ships within Fusion Middleware and licenses to third-party document-processing products. There is no evidence of active exploitation: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

Do: Apply the fix for CVE-2026-60392 released in the corresponding Oracle Critical Patch Update; Oracle lists only version 8.5.8 of the PDF Export SDK as affected, so consult the CPU advisory for the fixed release and upgrade accordingly. Inventory which Fusion Middleware components and OEMed products embed Outside In on your hosts and restrict local logon to those systems to limit the attacker's ability to stage the required user interaction. Given the low EPSS (0.3%), absence of a public PoC, and user-assisted local vector, patch at your normal maintenance cadence rather than treating it as an emergency.

7.8<1%
  • Oracle Outside In Technology (Outside In PDF Export SDK, Oracle Fusion Middleware) 8.5.8
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must open a malicious file or visit a malicious page. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60392.

This source does not provide full text. Read it at zerodayinitiative.com.