Description
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Oracle Managed File Transfer (MFT) Runtime Server component of Oracle Fusion Middleware. An attacker who can reach the MFT service over HTTP and has only low privileges can exploit this issue. The vulnerability is an instance of improper authentication (CWE‑306), allowing the attacker to bypass authentication controls and gain unauthorized access to the MFT server. Once authenticated, the attacker can take full control of the MFT installation, compromising confidentiality, integrity, and availability. Because the exploit changes the scope of the affected software, additional components may also be compromised as a consequence.

Affected Systems

The affected products are Oracle Managed File Transfer versions 12.2.1.4.0 and 14.1.2.0.0, released by Oracle Corporation. These versions are integrated into Oracle Fusion Middleware and expose HTTP interfaces for file transfer operations.

Risk and Exploitability

The CVSS base score of 9.9 indicates a severe impact on confidentiality, integrity, and availability. The vulnerability is not listed in the CISA KEV catalog, and the EPSS score of <1% indicates that the probability of public exploitation is very low, though the high CVSS 9.9 score points to severe impact. Because the attacker only needs low privileges and network access via HTTP, the attack surface is broad for both internal or external actors that can reach the service. Successful exploitation results in a full system takeover and can potentially affect other Oracle components due to the change in scope.

Generated by OpenCVE AI on August 4, 2026 at 03:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade MFT to a version that does not contain HTTP access to the MFT server to trusted IP ranges or internal networks.
  • Configure network firewalls to block unauthorized traffic to the MFT HTTP interface.
  • Segregate the MFT network segment and enforce strict VLAN or subnet controls to ensure only trusted hosts can reach the MFT service.

Generated by OpenCVE AI on August 4, 2026 at 03:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Code Execution via Improper Authentication in Oracle Managed File Transfer

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Full Control of Oracle Managed File Transfer

Sun, 26 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Full Control of Oracle Managed File Transfer

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle managed File Transfer
CPEs cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:managed_file_transfer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle managed File Transfer
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Managed File Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:03:05.702Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60537

cve-icon Vulnrichment

Updated: 2026-07-24T18:02:50.875Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function