Description
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as unauthorized read access to a subset of Oracle Managed File Transfer accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access and Denial of Service
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows a low‑privileged attacker with network access through the T3 or IIOP protocols to create, delete, or modify files, read restricted data, and trigger a hang or crash that results in a denial of service. The impact includes confidentiality, integrity, and availability compromise, as described by a CVSS 3.1 base score of 8.3. The weakness enables unauthorized manipulation of critical data and repeatedly disrupts the Oracle Managed File Transfer service.

Affected Systems

Oracle Corporation’s Managed File Transfer component of Oracle Fusion Middleware, specifically the MFT Runtime Server, is affected in versions 12.2.1.4.0 and 14.1.2.0.0. Users of these releases should verify their installed versions against the cited identifiers.

Risk and Exploitability

The EPSS score indicates very low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is network‑based, requiring only local or remote access through standard ports, and the low privilege requirement makes it attainable by a broad range of adversaries. The CVSS vector conveys limited confidentiality impact, but high integrity and availability effects, underscoring the risk when the weakness is present.

Generated by OpenCVE AI on September 17, 2026 at 04:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Oracle patch or Critical Patch Update for the affected MFT Runtime Server versions (12.2.1.4.0 and 14.1.2.0.0).
  • Restrict inbound network access to the MFT service by allowing T3 and IIOP traffic only from trusted hosts or subnets.
  • Enforce stricter role‑based access controls on the MFT server to ensure users have only the permissions necessary for their duties.

Generated by OpenCVE AI on September 17, 2026 at 04:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Oracle Managed File Transfer Vulnerability Enables File Manipulation and Denial of Service

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as unauthorized read access to a subset of Oracle Managed File Transfer accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).
First Time appeared Oracle
Oracle managed File Transfer
CPEs cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:managed_file_transfer:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle managed File Transfer
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Oracle Managed File Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:25:41.177Z

Reserved: 2026-08-31T15:40:57.333Z

Link: CVE-2026-83030

cve-icon Vulnrichment

Updated: 2026-09-16T15:54:56.455Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:11.207

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-83030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T05:00:14Z

Weaknesses