Description
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Outside In Technology’s Outside In Core component allows an unauthenticated attacker who has logged onto the infrastructure where the software runs to compromise the application. It requires human interaction from a person other than the attacker, but the attacker need only local access and no privileges. Successful exploitation can lead to complete takeover, resulting in confidentiality, integrity, and availability loss. The CVSS 3.1 base score is 7.8, reflecting high impact with the vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Affected Systems

The affected product is Oracle Outside In Technology (Outside In Core) version 8.5.8, which is part of Oracle Fusion Middleware. No other versions or products are listed as affected.

Risk and Exploitability

The high confidentiality, integrity, and availability impacts, coupled with a local attack vector requiring minimal effort, make this a pressing risk for any environment running Oracle Outside In Technology 8.5.8. The lack of a publicly disclosed patch or work‑around in the input emphasizes the need for immediate remediation.

Generated by OpenCVE AI on August 18, 2026 at 23:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and deploy the latest Oracle Outside In Technology 8.5.8 patch from Oracle’s official release or update channel.
  • Enforce least‑privilege access on the servers hosting Outside In Technology, ensuring that only trusted system accounts run the service and that standard users cannot elevate privileges.
  • Limit the ability of non‑privileged users to trigger or interact with the application’s privileged functions, and disable unnecessary features that expose high‑risk interfaces.
  • Monitor system and application logs for unusual activity or configuration changes that may indicate exploitation attempts.
  • Keep the underlying infrastructure up to date with security patches to reduce the overall attack surface.

Generated by OpenCVE AI on August 18, 2026 at 23:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Attack Compromise of Oracle Outside In Technology
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle outside In Technology
CPEs cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle outside In Technology
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Outside In Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:54.969Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60414

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:38.013

Modified: 2026-08-18T21:16:38.013

Link: CVE-2026-60414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses