Executive brief
Oracle Managed File Transfer is a platform used by organizations to securely move and manage large volumes of data between different systems. A security vulnerability in the MFT Runtime Server component allows an attacker with basic user credentials to take full control of the system over the network. This could lead to the theft of sensitive business data, disruption of automated file transfers, and unauthorized access to connected corporate infrastructure.
Technical details
This vulnerability affects the MFT Runtime Server component of Oracle Managed File Transfer. It is classified as easily exploitable, requiring only low-privileged user authentication and network access via HTTP. While the specific CWE is not detailed in the advisory, the impact is rated as high for confidentiality, integrity, and availability, effectively allowing a complete takeover of the affected instance. The vulnerability is present in versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.