CVE-2026-83094
moderateCritical Unauthenticated Takeover Flaw in Oracle Forms (Fusion Middleware)
CVE-2026-83094 is a critical vulnerability in Oracle Forms (component: Forms Services, C/S, Charmode) within Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges or user interaction, and successful attacks result in complete takeover of Oracle Forms with high impact to confidentiality, integrity, and availability (CVSS 3.1: 9.8). Organizations running the affected Forms versions as part of on-premises middleware stacks or business applications built on Forms are at risk, particularly if Forms Services endpoints are reachable from untrusted networks. No public proof of concept is known and the flaw is not on the CISA KEV list, but the combination of no authentication and full compromise makes patching urgent. Oracle addressed this via its Critical Patch Update process.
What to do: Apply the Oracle Critical Patch Update that remediates this issue for Forms 12.2.1.19.0 and 14.1.2.0.0 as soon as possible. Verify whether Forms Services (C/S, Charmode) endpoints are exposed to untrusted networks and restrict access via firewall rules, reverse proxies, or VPN if internet exposure is not required. After patching, review Forms server logs for unexplained sessions, unexpected runtime processes, or configuration changes that could indicate prior compromise.
| Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode) | 12.2.1.19.0 |
| Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.