Description
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local vulnerability in Oracle Outside In Technology allows an attacker who is not authenticated but has access to the same infrastructure to compromise the application. The attacker needs to rely on a secondary user to provide the necessary human interaction to trigger the exploit. Once successful, the attacker can take full control of the service, exposing all data and disrupting business operations by compromising confidentiality, integrity, and availability.

Affected Systems

Oracle Outside In Technology 8.5.8 - part of Oracle Fusion Middleware, component Outside In Core - is affected. All installations running the specified version are vulnerable; no other versions are listed.

Risk and Exploitability

The CVSS 7.8 score marks this as a high-severity flaw. EPSS is <1%, indicating a very low but nonzero likelihood of exploitation. The issue is not listed in CISA KEV. The vulnerability requires an attacker who is not authenticated but has local logon to the same infrastructure and relies on a human user to trigger the exploit. While it does not enable remote exploitation without local access, the presence of users with local privileges can still pose significant risk. Mitigation measures—such as isolating the machine that runs Outside In Technology, enforcing strict local access controls, and monitoring logs—can reduce the risk, but a vendor patch is recommended to close the vulnerability.

Generated by OpenCVE AI on August 21, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle‑issued security patch for Oracle Outside In Technology 8.5.8 that removes the privilege escalation flaw.
  • Enforce strict local access controls by isolating the machine that runs Outside In Technology and ensuring that only trusted, authenticated users can interact with it.
  • Continuously monitor application and system logs for anomalies that may indicate an exploitation attempt and investigate any suspicious events promptly.

Generated by OpenCVE AI on August 21, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Exploit Leading to Full Takeover of Oracle Outside In Technology

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Takeover of Oracle Outside In Technology
Weaknesses CWE-284
CWE-285

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Takeover of Oracle Outside In Technology
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle outside In Technology
CPEs cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle outside In Technology
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Outside In Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T14:42:52.039Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60412

cve-icon Vulnrichment

Updated: 2026-08-20T14:37:48.184Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:37.750

Modified: 2026-08-21T14:51:00.440

Link: CVE-2026-60412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T18:00:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data