ZeroHour

CVE-2026-83029

niche

Critical Broken Access Control in Oracle Managed File Transfer Runtime Server

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

Oracle Managed File Transfer (MFT), a component of Oracle Fusion Middleware, contains an easily exploitable broken access control flaw in the MFT Runtime Server affecting versions 12.2.1.4.0 and 14.1.2.0.0. A remote attacker holding only low-privileged (authenticated) credentials and network access via HTTP can trigger the flaw, and because the vulnerability carries a scope change, successful attacks may also significantly impact products beyond MFT itself. Exploitation gives the attacker unauthorized ability to create, delete, or modify critical data and full unauthorized read access to all data accessible through Oracle Managed File Transfer. Organizations running either affected version, particularly with the MFT Runtime Server reachable beyond internal trusted networks, are most at risk. No public proof-of-concept exists, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported to date.

What to do: Apply the current Oracle Critical Patch Update (CPU) to MFT Runtime Server on both 12.2.1.4.0 and 14.1.2.0.0, as Oracle remediates Fusion Middleware flaws through its quarterly CPU cycle. Until patched, restrict HTTP access to the MFT Runtime Server to trusted networks or VPN, and audit low-privileged MFT accounts for legitimacy and least privilege. Review MFT audit and transfer logs for unexpected data creation, deletion, modification, or reads attributable to low-privilege users, which could indicate attempted or successful exploitation.

Affected
Oracle Fusion Middleware — Oracle Managed File Transfer (MFT Runtime Server)
Estimated exposure
nicheunknown; plausibly on the order of hundreds to low thousands of enterprise MFT deployments worldwide — Oracle MFT is licensed enterprise middleware with no public active-install counts or reliable internet-scan fingerprints, so no firm number exists; deployments of this product class are typically concentrated in large enterprises in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as unauthorized access to critical data or complete access to all Oracle Managed File Transfer accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.