CVE-2026-60545

Oracle · Oracle Managed File Transfer

A high-severity vulnerability in the MFT Runtime Server of Oracle Managed File Transfer allows authenticated attackers to compromise the system via network access.

Executive summary

A high-severity vulnerability in Oracle Managed File Transfer allows low-privileged attackers to gain unauthorized control over the MFT Runtime Server.

Vulnerability

This flaw affects the MFT Runtime Server component and is easily exploitable by a low-privileged attacker via HTTP, resulting in the potential for a complete takeover of the affected product.

Business impact

Because Managed File Transfer systems often handle sensitive data transfers, the compromise of this component could lead to significant data breaches or unauthorized access to file repositories. The CVSS score of 8.8 reflects the high risk to confidentiality, integrity, and availability of managed file operations.

Remediation

Immediate Action: Identify all instances of Oracle Managed File Transfer and apply the security updates specified in the July 2026 Oracle Critical Patch Update.

Proactive Monitoring: Review audit logs for unauthorized file access attempts or anomalous configuration changes within the MFT Runtime Server.

Compensating Controls: Restrict access to the MFT management interface to authorized IP addresses only and ensure that service accounts operate with the principle of least privilege.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Administrators should treat this vulnerability with high urgency. Patching is the only reliable way to eliminate the underlying flaw, and organizations should move to verify their patch status against the July 2026 Oracle security advisories immediately.