Junglewise Threat Intelligence

CVE-2026-60549: Oracle Managed File Transfer takeover in MFT Runtime Server

CVE-2026-60549 · Severity: high · CVSS 8.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle Managed File Transfer, a solution used for secure data exchange between organizations, contains a vulnerability in its runtime server component. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the system. This could lead to the unauthorized access, modification, or deletion of sensitive files being transferred through the platform.

Technical details

A vulnerability exists in the MFT Runtime Server component of Oracle Managed File Transfer (versions 12.2.1.4.0 and 14.1.2.0.0). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific CWE is not detailed in the advisory, the impact is rated for high Confidentiality, Integrity, and Availability loss, effectively allowing a complete takeover of the affected component. No user interaction is required for exploitation. Organizations should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-60549 by Oracle

References