Description
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to compromise the Oracle Managed File Transfer runtime with only low privilege and simple HTTP network access. Successful exploitation would give the attacker control over the MFT component, resulting in loss of confidentiality, integrity, and availability of the system. The CVSS 3.1 base score of 8.8 indicates a high‑severity issue, with all three core impacts rated high. The weakness is a missing authentication/authorization control flaw (CWE‑306).

Affected Systems

Oracle Managed File Transfer version 12.2.1.4.0 and 14.1.2.0.0 are affected. Only these specific builds are vulnerable; newer or previous builds are not listed as impacted.

Risk and Exploitability

The EPSS score is reported as less than 1%, meaning the probability of exploitation at this time is very low, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the attack vector is remote via HTTP and the attacker requires only low privileges. If an attacker is able to send crafted requests, they can gain full control of the MFT instance. The high CVSS score and availability of an essentially zero‑denial deniability exploit path warrant prompt attention.

Generated by OpenCVE AI on August 4, 2026 at 03:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied security patch for Oracle Managed File Transfer 12.2.1.4.0 and 14.1.2.0.0 to eliminate the flaw.
  • Limit HTTP access to the MFT service to trusted networks and enforce strong authentication mechanisms to prevent low‑privileged exploitation.
  • Enable detailed logging for MFT operations and regularly audit logs for anomalous activity that might indicate exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 03:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Oracle Managed File Transfer Remote Code Execution via Low‑Privilege HTTP Access

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit in Oracle Managed File Transfer
Weaknesses CWE-284

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit in Oracle Managed File Transfer
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle managed File Transfer
CPEs cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:managed_file_transfer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle managed File Transfer
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Managed File Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T11:18:49.525Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60549

cve-icon Vulnrichment

Updated: 2026-07-27T11:18:38.706Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function