Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60549

CVE-2026-60549: Oracle Managed File Transfer RCE Flaw

CVE-2026-60549 is a remote code execution vulnerability in Oracle Managed File Transfer that allows low-privileged attackers to fully compromise the system. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-60549 Overview

CVE-2026-60549 is a high-severity vulnerability in the Oracle Managed File Transfer (MFT) product within Oracle Fusion Middleware. The flaw resides in the MFT Runtime Server component and affects supported versions 12.2.1.4.0 and 14.1.2.0.0. A low-privileged attacker with network access over HTTP can exploit this issue to fully compromise the Oracle MFT instance. Oracle disclosed the vulnerability in the July 2026 Critical Patch Update advisory.

Critical Impact

Successful exploitation results in complete takeover of Oracle Managed File Transfer, with high impact to confidentiality, integrity, and availability.

Affected Products

  • Oracle Managed File Transfer 12.2.1.4.0
  • Oracle Managed File Transfer 14.1.2.0.0
  • Oracle Fusion Middleware (MFT Runtime Server component)

Discovery Timeline

  • 2026-07-21 - CVE-2026-60549 published to NVD
  • 2026-07-21 - Last updated in NVD database
  • July 2026 - Included in Oracle Critical Patch Update advisory

Technical Details for CVE-2026-60549

Vulnerability Analysis

The vulnerability exists in the MFT Runtime Server component of Oracle Managed File Transfer. Oracle describes the issue as easily exploitable, requiring only network access via HTTP and low-privileged authenticated access. Successful exploitation permits an attacker to take over the MFT instance, affecting confidentiality, integrity, and availability at the highest levels.

Oracle MFT handles secure file exchange for enterprise workloads, meaning a compromised instance exposes transferred payloads, credentials, and downstream integrations. The unchanged scope indicates the impact remains within the MFT security authority, yet full takeover of that authority is sufficient to pivot to connected systems.

Oracle has not released technical specifics beyond the advisory. The Oracle Security Alert July 2026 is the authoritative source for the patch and affected build details.

Root Cause

Oracle has not published the underlying weakness classification or CWE for this issue. The advisory only confirms that a low-privileged, network-adjacent request through HTTP can drive the MFT Runtime Server into a state that grants attacker takeover.

Attack Vector

The attack originates from the network over HTTP. The attacker must hold a low-privilege account on the target MFT instance. No user interaction is required, and complexity is low, which reflects a straightforward request-driven exploitation path against the MFT Runtime Server endpoints.

No public proof-of-concept exploit code is available. Refer to the Oracle advisory for the authoritative remediation guidance.

Detection Methods for CVE-2026-60549

Indicators of Compromise

  • Unexpected administrative or configuration changes within Oracle MFT (new users, altered transfer flows, modified endpoints).
  • Anomalous HTTP requests to MFT Runtime Server URLs from low-privileged accounts.
  • Outbound connections from MFT servers to unfamiliar external hosts following authenticated sessions.
  • New or modified files staged in MFT source or target directories outside normal transfer windows.

Detection Strategies

  • Review MFT audit logs for authenticated sessions performing privileged operations inconsistent with the user's role.
  • Correlate web access logs on the MFT Runtime Server for repeated requests to sensitive endpoints preceding configuration changes.
  • Baseline normal file transfer volume and alert on deviations that coincide with account activity anomalies.

Monitoring Recommendations

  • Forward Oracle Fusion Middleware and MFT logs to a centralized SIEM for correlation with identity and network telemetry.
  • Monitor Weblogic and MFT process behavior for unexpected child processes or scripting engine invocations.
  • Alert on privilege changes, credential resets, and role assignments within the MFT administration console.

How to Mitigate CVE-2026-60549

Immediate Actions Required

  • Apply the Oracle July 2026 Critical Patch Update fixes for Oracle Managed File Transfer 12.2.1.4.0 and 14.1.2.0.0 without delay.
  • Restrict network reachability to the MFT Runtime Server so only trusted management networks can send HTTP requests.
  • Audit MFT accounts and remove or disable low-privileged accounts that are no longer required.
  • Rotate credentials and API keys used by MFT integrations after patching.

Patch Information

Oracle addresses CVE-2026-60549 in the Oracle Security Alert July 2026. Administrators must apply the corresponding Critical Patch Update to both 12.2.1.4.0 and 14.1.2.0.0 deployments. No supported workaround replaces the patch.

Workarounds

  • Place the MFT Runtime Server behind a reverse proxy or WAF that enforces authentication controls and blocks anomalous HTTP methods.
  • Enforce network segmentation and firewall rules that permit MFT access only from designated administrative subnets.
  • Enable enhanced logging on MFT and Fusion Middleware components until patches are deployed for faster investigation of suspicious activity.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.