Description
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Outside In Technology product, part of Oracle Fusion Middleware, contains a flaw in its Outside In PDF Export SDK that allows an unauthenticated attacker who has logged onto the infrastructure hosting the tool to take full control of the component. The bug arises from improper deserialization of data, and an attacker does not need any application‑level credentials. Although taking advantage of the flaw requires a separate user to click or otherwise interact with the target application‘s user interface, the effect of a successful exploitation is complete compromise of confidentiality, integrity, and availability of all data handled by the SDK.

Affected Systems

Only Oracle Outside In Technology version 8.5.8 is known to be affected. No other major releases or separate products from Oracle Fusion Middleware are listed as impacted. The flaw lies within the component named Outside In PDF Export SDK.

Risk and Exploitability

The weakness has a CVSS base score of 7.8, indicating a high‑severity vulnerability. The EPSS score of <1% shows that the likelihood of exploitation in the wild is low, and the flaw is not currently catalogued in CISA’s KEV list. Attackers must have local logon permissions to the host where the application runs and must trigger the exploit through a user‑initiated action in the application; no remote network access is required. Because the flaw permits an attacker to fully takeover the Oracle Outside In Technology component, environments that provide local logon rights to users who can reach the PDF Export SDK face elevated risk and should act quickly.

Generated by OpenCVE AI on August 21, 2026 at 16:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or update Oracle Outside In Technology to the latest version that includes the fix for this flaw.
  • Limit local logon rights on the infrastructure hosting the product to only users who truly require that level of access.
  • If the PDF Export SDK is not critical to business operations, disable or isolate it from non-trusted processes.
  • Implement monitoring for unauthorized or suspicious interactions with the PDF Export SDK and maintain detailed audit logs.

Generated by OpenCVE AI on August 21, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Local Unauthorized Takeover in Oracle Outside In Technology PDF Export SDK

Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle outside In Technology
CPEs cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle outside In Technology
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Outside In Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T13:47:55.233Z

Reserved: 2026-07-08T15:51:40.534Z

Link: CVE-2026-60392

cve-icon Vulnrichment

Updated: 2026-08-19T13:47:50.408Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:37.510

Modified: 2026-08-21T14:51:24.727

Link: CVE-2026-60392

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T16:30:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data