Executive brief
Oracle Managed File Transfer, a system used by organizations to securely move and manage large volumes of data, contains a critical security flaw in its Runtime Server component. An attacker with low-level access to the network can exploit this vulnerability to take complete control of the system. Because this tool often connects to many other internal systems, a successful attack could allow an intruder to move beyond the file transfer server and impact other parts of the corporate network.
Technical details
A critical vulnerability exists in the MFT Runtime Server component of Oracle Managed File Transfer (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is categorized by a CVSS 3.1 score of 9.9, indicating a high impact on confidentiality, integrity, and availability. The attack vector is network-based via HTTP and requires only low-privileged credentials with no user interaction. Notably, the vulnerability involves a scope change (S:C), meaning an exploit can impact resources beyond the security scope of the Managed File Transfer product itself. Successful exploitation can result in a complete takeover of the affected server.
Affected products
- Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update
- 2026-07-21: disclosed