ZeroHour

CVE-2026-83093

moderate

Unauthenticated Data Disclosure in Oracle Forms Services (Fusion Middleware)

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83093 is a high-severity (CVSS 8.6) vulnerability in the Forms Services, C/S, and Charmode components of Oracle Forms, part of Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction. Successful attacks result in unauthorized access to critical data or complete access to all Oracle Forms accessible data; because the scope changes, the impact may extend beyond Oracle Forms to additional products that share its data. Organizations running the affected Forms versions—commonly legacy enterprise and EBS-style applications exposed through Forms Servlet endpoints—are at risk if the service is reachable over a network. No public proof of concept is known and the CVE is not on the CISA KEV list, so exploitation status is currently none known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83093 to all Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 installations. Restrict network access to Forms Services HTTP endpoints (e.g., forms/frmservlet) via firewall rules or VPN so they are not reachable by unauthenticated internet users. Audit access logs for anomalous unauthenticated requests, and inventory what downstream data and integrated systems Forms can reach, since the scope-change rating means impacts may extend beyond the Forms tier.

Affected
Oracle Forms (Oracle Fusion Middleware) - Forms Services, C/S, Charmode components12.2.1.19.0, 14.1.2.0.0
Estimated exposure
moderate≈ a few thousand internet-exposed Forms endpoints, plus tens of thousands of internal/enterprise deployments (estimate) — Oracle Forms is legacy enterprise middleware typically deployed on corporate networks; public internet scans of Forms Servlet (frmservlet) endpoints historically show low-thousands exposure, with a larger unseen internal install base, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.