ZDI-CAN-29370: ZDI-26-635: Oracle Outside In Technology PDF File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must open a malicious file or visit a malicious page. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60392.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Outside In Technologyto a version that resolves this vulnerability.Patch ZDI-26-635
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must induce the target to open a malicious PDF file or visit a malicious page. Successful exploitation can result in arbitrary code execution on the affected Oracle Outside In Technology installation.
Is user interaction required?
Yes. Exploitation requires the target to open the malicious file or visit the malicious page; the provided information does not describe a no-interaction exploitation path.