Junglewise Threat Intelligence

CVE-2026-83029: Oracle Managed File Transfer authorization bypass

CVE-2026-83029 · Severity: critical · CVSS 9.6 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Managed File Transfer is a file exchange component of Oracle Fusion Middleware used to securely transfer files across organizations. A network-accessible vulnerability allows attackers with low-level credentials to read, modify, or delete sensitive files and data without proper authorization, potentially impacting the confidentiality and integrity of business-critical information.

Technical details

This vulnerability in the MFT Runtime Server component is an authorization bypass that allows low-privileged authenticated users to perform unauthorized operations on Oracle Managed File Transfer data. The flaw is network-accessible via HTTP and requires valid (low-privilege) credentials to exploit, but does not require user interaction. Successful exploitation enables unauthorized access to, modification of, or deletion of critical data managed by Oracle Managed File Transfer, with potential scope change affecting additional Oracle Fusion Middleware products. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0; patches from Oracle are expected in the September 2026 CPU release.

Affected products

  • Oracle Managed File Transfer 12.2.1.4.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed
  • 2026-09: patched: Expected in Oracle Critical Patch Update (CPU) September 2026

References