ZeroHour

CVE-2026-83030

niche

Low-Privilege Data Tampering and DoS in Oracle Managed File Transfer via T3/IIOP

CVSS 3.1
8.3 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83030 is a high-severity (CVSS 8.3) vulnerability in the MFT Runtime Server component of Oracle Managed File Transfer, affecting versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware. A remote attacker with only low-privileged credentials and network access to the T3 or IIOP protocols can compromise the MFT instance, gaining unauthorized ability to create, delete, or modify critical data, read a subset of MFT-accessible data, and repeatedly crash or hang the service for a complete denial of service. Because exploitation requires valid low-privilege credentials and access to Oracle WebLogic-style Java protocols (T3/IIOP), it primarily threatens internet-exposed or poorly segmented MFT deployments where those ports are reachable. No public proof-of-concept code is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Organizations running MFT for business file transfers should treat this as a data-integrity and availability risk to patch promptly.

What to do: Apply the Oracle Critical Patch Update that fixes this flaw to MFT 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available for your environment. Restrict or block T3 and IIOP access at the network perimeter so only trusted admin/application hosts can reach those ports, and audit MFT configurations, transfer definitions, and audit logs for unauthorized changes or repeated crashes. Rotate low-privileged credentials that have access to T3/IIOP if exposure is suspected.

Affected
Oracle Managed File Transfer (Fusion Middleware, MFT Runtime Server)12.2.1.4.0
Oracle Managed File Transfer (Fusion Middleware, MFT Runtime Server)14.1.2.0.0
Estimated exposure
nichelikely low thousands of enterprise deployments, with only a small fraction internet-exposed (unknown exact count) — Oracle MFT is licensed enterprise middleware typically deployed inside corporate networks, and public scan data shows only a modest number of internet-exposed T3/IIOP endpoints, so the reachable population is plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as unauthorized read access to a subset of Oracle Managed File Transfer accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H

In the news

No ingested article mentions this CVE yet.