Description
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a missing authentication control (CWE‑306) in Oracle Managed File Transfer’s Runtime Server, enabling a low‑privileged attacker to gain unauthorized access over the network via the HTTP interface. The vulnerability can result in full compromise of the MFT service, allowing an attacker to read, modify, delete, or exfiltrate data and disrupt availability. The likely attack vector is anonymous HTTP requests to an exposed endpoint.

Affected Systems

Oracle Managed File Transfer versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. The vulnerability targets the MFT Runtime Server component that exposes an HTTP endpoint.

Risk and Exploitability

The CVSS base score is 8.8, indicating high severity with impacts to confidentiality, integrity, and availability. The EPSS score is less than 1%, suggesting limited exploitation probability. The KEV catalog does not list this CVE, but the low attack complexity and no user interaction mean that an attacker who can reach the HTTP interface can exploit the flaw remotely. Although widespread exploitation is considered unlikely, the potential for complete service takeover requires prompt patching.

Generated by OpenCVE AI on August 4, 2026 at 03:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch that addresses the issue in Managed File Transfer 12.2.1.4.0 and 14.1.2.0.0
  • Restrict network access to the MFT Runtime Server’s HTTP interface using firewalls or VPNs so that only trusted IP addresses can reach the service
  • Enforce TLS/HTTPS and enable robust authentication (client certificates or multi‑factor authentication) on all MFT endpoints to limit unauthorized access
  • If a patch cannot be applied immediately, disable the exposed HTTP endpoint or place the MFT service behind a reverse proxy that performs authentication and rate limiting

Generated by OpenCVE AI on August 4, 2026 at 03:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title HTTP Access Vulnerability Enables Full Takeover of Oracle Managed File Transfer

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Remote HTTP Vulnerability Enables Takeover of Oracle Managed File Transfer
Weaknesses CWE-284
CWE-285

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Remote HTTP Vulnerability Enables Takeover of Oracle Managed File Transfer
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle managed File Transfer
CPEs cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:managed_file_transfer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle managed File Transfer
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Managed File Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T11:10:47.062Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60545

cve-icon Vulnrichment

Updated: 2026-07-27T11:10:26.308Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function