Description
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Outside In Technology’s Outside In Core component allows an unauthenticated attacker who has logged onto the infrastructure where the software runs to compromise the application. It requires the attacker to have local access and no privileges, and it also requires human interaction from a person other than the attacker. Successful exploitation can lead to complete takeover, resulting in confidentiality, integrity, and availability loss. The CVSS 3.1 base score is 7.8, reflecting high impact with the vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Affected Systems

The affected product is Oracle Outside In Technology (Outside In Core) version 8.5.8, which is part of Oracle Fusion Middleware. No other versions or products are listed as affected.

Risk and Exploitability

The high confidentiality, integrity, and availability impacts, coupled with a local attack vector requiring no privileges, underscore the risk of this vulnerability. The EPSS score of <1% indicates a low probability of exploitation at any given time; however, the CVSS base score of 7.8 and the potential for complete takeover underscore the need for immediate remediation, preferably through an official vendor patch if available.

Generated by OpenCVE AI on August 21, 2026 at 19:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and deploy the latest Oracle Outside In Technology 8.5.8 patch from Oracle’s official release or update channel.
  • Enforce least‑privilege access on the servers hosting Outside In Technology, ensuring that only trusted system accounts run the service and that standard users cannot elevate privileges.
  • Limit the ability of non‑privileged users to trigger or interact with the application’s privileged functions, and disable unnecessary features that expose high‑risk interfaces.
  • Monitor system and application logs for unusual activity or configuration changes that may indicate exploitation attempts.
  • Keep the underlying infrastructure up to date with security patches to reduce the overall attack surface.

Generated by OpenCVE AI on August 21, 2026 at 19:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Compromise of Oracle Outside In Technology

Fri, 21 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Attack Compromise of Oracle Outside In Technology
Weaknesses CWE-284
CWE-862

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Attack Compromise of Oracle Outside In Technology
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle outside In Technology
CPEs cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle outside In Technology
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Outside In Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T15:00:06.706Z

Reserved: 2026-07-08T15:51:40.535Z

Link: CVE-2026-60414

cve-icon Vulnrichment

Updated: 2026-08-20T14:59:28.306Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:38.013

Modified: 2026-08-21T14:50:04.373

Link: CVE-2026-60414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor