Oracle disclosed a critical (CVSS 9.6) vulnerability in the MFT Runtime Server component of Oracle Managed File Transfer that lets a low-privileged, remote attacker fully compromise file transfer data and reach beyond the product's own security scope.
What Is It
The flaw sits in the MFT Runtime Server component of Oracle Managed File Transfer, part of Oracle Fusion Middleware. Oracle rates it "easily exploitable": an attacker needs network access over HTTP and only low privileges; no user interaction required.
Successful exploitation yields unauthorized creation, deletion, or modification of critical data or all data accessible to Oracle Managed File Transfer, plus unauthorized read access up to complete access to that same data set. Availability is not impacted.
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N, base score 9.6, severity CRITICAL.
Why It Matters
Two things push this above a routine middleware bug.
First, the scope change (S:C). Oracle explicitly notes that while the vulnerability lives in Oracle Managed File Transfer, attacks may significantly impact additional products. That suggests the blast radius may not be confined to MFT itself, though Oracle does not enumerate which downstream products are affected or under what conditions.
Second, the low bar to entry. Attack complexity is low, no user interaction is needed, and the attacker only needs low privileges. PR:L means the attacker must still hold some valid credentials or an authenticated session on the target, it is not pre-authentication access, but it does not require administrative or otherwise elevated rights. Combined with network reachability over HTTP, that makes internet-exposed or broadly reachable MFT Runtime Servers a high-value target for anyone who already holds, phishes, or buys a low-tier account.
Managed file transfer platforms are, by design, aggregation points for sensitive data in motion. Full read and write access to everything an MFT instance can reach is a serious confidentiality and integrity event.
There is no CISA KEV entry for CVE-2026-83029 as of this writing, so active exploitation is not currently confirmed by CISA, and no KEV-mandated remediation deadline applies. The catalog is updated continuously; administrators should check it directly for the current status.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Managed File Transfer (Oracle Fusion Middleware)
- Component: MFT Runtime Server
- Affected supported versions: 12.2.1.4.0 and 14.1.2.0.0
Patch Status
The CVE was published 2026-09-15 with NVD status "Received." Oracle's security alert for this issue is the authoritative source for fix availability and applicable patches; administrators running either affected version should consult it directly and apply Oracle's guidance.
Sources
- NVD, CVE-2026-83029: https://nvd.nist.gov/vuln/detail/CVE-2026-83029
- Oracle Security Alerts (advisory index): https://www.oracle.com/security-alerts/
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog