ZeroHour

CVE-2026-83095

moderate

Unauthenticated Takeover Flaw in Oracle Forms Services (Fusion Middleware)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83095 is a critical (CVSS 9.8) vulnerability in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction, and successful attacks result in a complete takeover of Oracle Forms with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.19.0 and 14.1.2.0.0, which are commonly deployed in enterprise environments to serve legacy forms-based business applications. Because Oracle Forms endpoints are sometimes exposed to the internet to support remote users, unpatched instances present a direct path to full server compromise. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild has not been observed as of this analysis.

What to do: Apply the latest Oracle Critical Patch Update that remediates CVE-2026-83095 to installations running Oracle Forms 12.2.1.19.0 or 14.1.2.0.0. Restrict network access to Forms Services HTTP endpoints so they are reachable only from trusted networks or via VPN, and verify that Forms runtime servlets are not directly internet-exposed. Review HTTP access logs for anomalous unauthenticated requests to Forms endpoints and monitor affected servers for signs of compromise.

Affected
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)12.2.1.19.0, 14.1.2.0.0
Estimated exposure
moderatelikely a few thousand internet-exposed Oracle Forms/Fusion Middleware endpoints, plus a larger unknown population of internal enterprise deployments — Oracle Forms is legacy enterprise software with no public install counts; public internet scans (e.g., Shodan/Censys) typically show thousands of exposed Oracle Fusion Middleware endpoints, with Forms being a subset of those.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.