---
id: CVE-2026-60412
title: >-
  Vulnerability in the Oracle Outside In Technology product of Oracle Fusion
  Middleware (component: Outside In Core)
summary: >-
  Vulnerability in the Oracle Outside In Technology product of Oracle Fusion
  Middleware (component: Outside In Core).   The supported version that is
  affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated
  attacker with …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: oracle
product: outside_in_technology
affected:
  - outside_in_technology = 8.5.8
published: '2026-08-18'
updated: '2026-08-21'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-60412'
references:
  - url: 'https://www.oracle.com/security-alerts/cspuaug2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
epss: 0.00297
epssPercentile: 0.22599
ingestedAt: '2026-08-22T13:32:37.212Z'
---

## Overview

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core).   The supported version that is affected is 8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

## Affected

- `outside_in_technology = 8.5.8`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
