CVE-2026-83030
nicheLow-Privilege Data Tampering and DoS in Oracle Managed File Transfer via T3/IIOP
CVE-2026-83030 is a high-severity (CVSS 8.3) vulnerability in the MFT Runtime Server component of Oracle Managed File Transfer, affecting versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle Fusion Middleware. A remote attacker with only low-privileged credentials and network access to the T3 or IIOP protocols can compromise the MFT instance, gaining unauthorized ability to create, delete, or modify critical data, read a subset of MFT-accessible data, and repeatedly crash or hang the service for a complete denial of service. Because exploitation requires valid low-privilege credentials and access to Oracle WebLogic-style Java protocols (T3/IIOP), it primarily threatens internet-exposed or poorly segmented MFT deployments where those ports are reachable. No public proof-of-concept code is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Organizations running MFT for business file transfers should treat this as a data-integrity and availability risk to patch promptly.
What to do: Apply the Oracle Critical Patch Update that fixes this flaw to MFT 12.2.1.4.0 and 14.1.2.0.0 as soon as it is available for your environment. Restrict or block T3 and IIOP access at the network perimeter so only trusted admin/application hosts can reach those ports, and audit MFT configurations, transfer definitions, and audit logs for unauthorized changes or repeated crashes. Rotate low-privileged credentials that have access to T3/IIOP if exposure is suspected.
| Oracle Managed File Transfer (Fusion Middleware, MFT Runtime Server) | 12.2.1.4.0 |
| Oracle Managed File Transfer (Fusion Middleware, MFT Runtime Server) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as unauthorized read access to a subset of Oracle Managed File Transfer accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.