Executive brief
Oracle Managed File Transfer, a system used for secure data exchange between organizations, contains a critical vulnerability in its runtime server component. An attacker with low-level access to the network can exploit this flaw to take complete control of the system. This could lead to the theft of sensitive files, disruption of business operations, and potential unauthorized access to other connected corporate systems.
Technical details
A critical vulnerability exists in the MFT Runtime Server component of Oracle Managed File Transfer (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable via the HTTP protocol and requires only low-privileged authentication. Successful exploitation results in a 'scope change' (S:C), meaning the attacker can move beyond the MFT application to impact other parts of the environment. The vulnerability allows for a complete takeover of the MFT instance, impacting confidentiality, integrity, and availability. Users are advised to consult the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published