{"cve":"CVE-2026-60392","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"8.5.8"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Oracle Outside In Technology","source":"cna","vendor":"Oracle Corporation"},"product":"outside_in_technology","vendor":"oracle"}],"created":"2026-08-18T22:45:02.978445+00:00","title":"Local Unauthorized Takeover in Oracle Outside In Technology PDF Export SDK","updated":"2026-08-21T16:30:06.980524+00:00","vendors":["oracle","oracle$PRODUCT$outside_in_technology"]},"epss":{"score":0.00319},"mitre":{"cpes":["cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"],"created":"2026-08-18T20:58:53.598000+00:00","description":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK).   The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.8,"vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/60xxx/CVE-2026-60392.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-19T13:47:55.233000+00:00","vendors":["oracle","oracle$PRODUCT$outside_in_technology"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"],"created":"2026-08-18T21:16:37.510000+00:00","description":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK).   The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.8,"vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-60392.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-21T14:51:24.727000+00:00","vendors":["oracle","oracle$PRODUCT$outside_in_technology"],"weaknesses":["CWE-502"]},"opencve":{"changes":[{"created":"2026-08-18T21:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK).   The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$outside_in_technology"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$outside_in_technology"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":7.8,"vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"958d7c1a-a34e-466e-be77-c9688e27fcb6"},{"created":"2026-08-19T14:30:00+00:00","data":[{"details":{"added":["CWE-502"],"removed":[]},"type":"weaknesses"}],"id":"45d2c1f7-b754-4de5-a1df-c53f7ab79cd4"},{"created":"2026-08-21T03:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"3f54f6eb-4665-49e7-ba04-9c2c5856f2e9"},{"created":"2026-08-21T16:45:00+00:00","data":[{"details":{"new":"Local Unauthorized Takeover in Oracle Outside In Technology PDF Export SDK","old":null},"type":"title"}],"id":"9549e8e2-fe10-40a8-b75f-eb3db77a7782"}],"cpes":{"data":["cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-08-18T20:58:53.598000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK).   The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":7.8,"vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00319},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Local Unauthorized Takeover in Oracle Outside In Technology PDF Export SDK","provider":"enrichment"},"updated":{"data":"2026-08-21T16:30:06.980524+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$outside_in_technology"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-502"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-08-18T20:58:53.598000+00:00","description":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export SDK).   The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-08-19T13:47:50.408000+00:00","vendors":[],"vulnrichment_repo_path":"2026/60xxx/CVE-2026-60392.json","weaknesses":["CWE-502"]}}