Description
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as unauthorized access to critical data or complete access to all Oracle Managed File Transfer accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification, deletion, or creation leading to confidentiality and integrity loss
Action: Immediate Patch
AI Analysis

Impact

Oracle Managed File Transfer contains a flaw that lets a low‑privilege attacker who can reach the service over HTTP perform unauthorized creation, deletion, or modification of data. The flaw is a known access control weakness (CWE-284) that enables this manipulation, resulting in both confidentiality and integrity compromise as the attacker can alter or change the effective scope of the application, enabling the attacker to affect additional components that rely on the same runtime environment.

Affected Systems

The affected product is Oracle Corporation's Managed File Transfer component of Oracle Fusion Middleware. Vulnerable releases are 12.2.1.4.0 and 14.1.2.0.0; no other versions are listed as affected, though other Oracle products that share the same runtime could be impacted through scope change.

Risk and Exploitability

The CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N yields a base score of 9.6, indicating a severe confidentiality and integrity impact. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because the vector includes a changed scope (S:C) and the product shares its runtime with other Oracle Fusion Middleware components, a successful attack could also affect additional products that use the same MFT Runtime Server. Exploitation would require only network access over HTTP and does not require user interaction or elevated privileges, enabling a low‑privilege attacker to send crafted requests to the MFT Runtime Server.

Generated by OpenCVE AI on September 17, 2026 at 05:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade to a fixed version of Oracle Managed File Transfer, if available.
  • Restrict network access to the MFT service to trusted or unauthenticated HTTP traffic.
  • Enable detailed auditing and monitoring of file operations, logging unauthorized create, delete, or modify actions for rapid detection.

Generated by OpenCVE AI on September 17, 2026 at 05:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as unauthorized access to critical data or complete access to all Oracle Managed File Transfer accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle managed File Transfer
CPEs cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:managed_file_transfer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle managed File Transfer
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Managed File Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:25:47.132Z

Reserved: 2026-08-31T15:40:57.332Z

Link: CVE-2026-83029

cve-icon Vulnrichment

Updated: 2026-09-16T15:43:25.277Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:11.037

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:00:09Z

Weaknesses