CVE-2026-83093
moderateUnauthenticated Data Disclosure in Oracle Forms Services (Fusion Middleware)
CVE-2026-83093 is a high-severity (CVSS 8.6) vulnerability in the Forms Services, C/S, and Charmode components of Oracle Forms, part of Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle Forms accessible data; because the scope changes, the impact may extend beyond Oracle Forms to additional products that share its data. Organizations running the affected Forms versions—commonly legacy enterprise and EBS-style applications exposed through Forms Servlet endpoints—are at risk if the service is reachable over a network. No public proof of concept is known and the CVE is not on the CISA KEV list, so exploitation status is currently none known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83093 to all Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 installations. Restrict network access to Forms Services HTTP endpoints (e.g., forms/frmservlet) via firewall rules or VPN so they are not reachable by unauthenticated internet users. Audit access logs for anomalous unauthenticated requests, and inventory what downstream data and integrated systems Forms can reach, since the scope-change rating means impacts may extend beyond the Forms tier.
| Oracle Forms (Oracle Fusion Middleware) - Forms Services, C/S, Charmode components | 12.2.1.19.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.