ZeroHour

CVE-2026-83094

moderate

Critical Unauthenticated Takeover Flaw in Oracle Forms (Fusion Middleware)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83094 is a critical vulnerability in Oracle Forms (component: Forms Services, C/S, Charmode) within Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks result in complete takeover of Oracle Forms with high impact to confidentiality, integrity, and availability (CVSS 3.1: 9.8). Organizations running the affected Forms versions as part of on-premises middleware stacks or business applications built on Forms are at risk, particularly if Forms Services endpoints are reachable from untrusted networks. No public proof of concept is known and the flaw is not on the CISA KEV list, but the combination of no authentication and full compromise makes patching urgent. Oracle addressed this via its Critical Patch Update process.

What to do: Apply the Oracle Critical Patch Update that remediates this issue for Forms 12.2.1.19.0 and 14.1.2.0.0 as soon as possible. Verify whether Forms Services (C/S, Charmode) endpoints are exposed to untrusted networks and restrict access via firewall rules, reverse proxies, or VPN if internet exposure is not required. After patching, review Forms server logs for unexplained sessions, unexpected runtime processes, or configuration changes that could indicate prior compromise.

Affected
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)12.2.1.19.0
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)14.1.2.0.0
Estimated exposure
moderate≈ low thousands of internet-exposed Forms endpoints; most deployments are internal enterprise systems — Oracle Forms is enterprise middleware typically deployed on-premises behind firewalls; public scan services historically show on the order of a few thousand exposed Oracle Forms/Reports endpoints, with the majority of the install base not…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.