ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
ZDI disclosed a heap-based buffer overflow in Oracle Outside In Technology's PostScript parsing (CVE-2026-60412) enabling user-triggered remote code execution.
Zero Day Initiative published ZDI-26-636, a CVSS 7.8 heap-based buffer overflow in PostScript file parsing within Oracle Outside In Technology. Remote attackers can execute arbitrary code when the target opens a malicious file or visits a malicious page, making user interaction a requirement. The vulnerability is tracked as CVE-2026-60412. The advisory reports no exploitation.
- Heap-based buffer overflow in PostScript parsing, tracked as CVE-2026-60412
- CVSS 7.8 remote code execution in Oracle Outside In Technology
- User interaction required: malicious file or page
- Disclosed as ZDI-26-636; no in-the-wild exploitation reported
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-60412 | PostScript Parsing Heap Overflow in Oracle Outside In Technology 8.5.8 CVE-2026-60412 is a flaw in the Outside In Core component of Oracle Outside In Technology 8.5.8, a document-parsing engine distributed as part of Oracle Fusion Middleware; the CVE is classified as CWE-502 (deserialization of untrusted data), while the related ZDI advisory (ZDI-26-636) describes it as a heap-based buffer overflow triggered when parsing PostScript files. The attack vector is local (AV:L): an unauthenticated attacker must have logon to the infrastructure where Outside In executes, and successful exploitation additionally requires human interaction from someone other than the attacker, typically a user or service processing an attacker-supplied file. A successful attack can result in takeover of the Outside In Technology instance with high confidentiality, integrity and availability impact (CVSS 3.1 7.8), and the ZDI advisory characterizes the outcome as remote code execution. The affected version in Oracle's advisory is 8.5.8, so organizations running this release directly or bundled inside Oracle Fusion Middleware products are in scope. Exploitation has not been observed: there is no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (22nd percentile). Do: Apply the Outside In Technology fix from the Oracle Critical Patch Update covering this CVE, upgrading 8.5.8 to the patched release Oracle identifies and updating any Fusion Middleware products that bundle the engine. Until patched, restrict which accounts can perform Outside In document conversions and limit processing of untrusted PostScript and similar files, since exploitation requires local logon plus user interaction. No public PoC or in-the-wild exploitation is known, but monitor Oracle support notes for the exact patched version and dependent product updates. | 7.8 | <1% |
| large≈ tens of thousands of Oracle middleware/document-processing deployments (estimated; no public install counts) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60412.
This source does not provide full text. Read it at zerodayinitiative.com.