Description
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local vulnerability in Oracle Outside In Technology allows an attacker who is not authenticated but has access to the same infrastructure to compromise the application. The attacker needs to rely on a secondary user to provide the necessary human interaction to trigger the exploit. Once successful, the attacker can take full control of the service, exposing all data and disrupting business operations by compromising confidentiality, integrity, and availability.

Affected Systems

Oracle Outside In Technology 8.5.8 – part of Oracle Fusion Middleware, component Outside In Core – is affected. All installations running the specified version are vulnerable; no other versions are listed.

Risk and Exploitability

The CVSS 7.8 score marks this as a high‑severity flaw. EPSS is not available and the issue is not listed in CISA KEV. The local attack vector and requirement for human interaction lower the chances of spontaneous remote exploitation but still pose significant risk when users with local access are in place. Proper network segmentation, restrictive local access permissions, and user awareness can mitigate potential attacks but a vendor patch is recommended to close the vulnerability.

Generated by OpenCVE AI on August 18, 2026 at 23:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle‑issued security patch for Oracle Outside In Technology 8.5.8 that removes the privilege escalation flaw.
  • Enforce strict local access controls by isolating the machine that runs Outside In Technology and ensuring that only trusted, authenticated users can interact with it.
  • Continuously monitor application and system logs for anomalies that may indicate an exploitation attempt and investigate any suspicious events promptly.

Generated by OpenCVE AI on August 18, 2026 at 23:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Takeover of Oracle Outside In Technology
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle outside In Technology
CPEs cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle outside In Technology
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Outside In Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:54.344Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:37.750

Modified: 2026-08-18T21:16:37.750

Link: CVE-2026-60412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses