CVE-2026-83095
moderateUnauthenticated Takeover Flaw in Oracle Forms Services (Fusion Middleware)
CVE-2026-83095 is a critical (CVSS 9.8) vulnerability in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware. It is easily exploitable by an unauthenticated attacker with network access via HTTP, requiring no privileges and no user interaction, and successful attacks result in a complete takeover of Oracle Forms with high impact on confidentiality, integrity, and availability. Affected supported versions are 12.2.1.19.0 and 14.1.2.0.0, which are commonly deployed in enterprise environments to serve legacy forms-based business applications. Because Oracle Forms endpoints are sometimes exposed to the internet to support remote users, unpatched instances present a direct path to full server compromise. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild has not been observed as of this analysis.
What to do: Apply the latest Oracle Critical Patch Update that remediates CVE-2026-83095 to installations running Oracle Forms 12.2.1.19.0 or 14.1.2.0.0. Restrict network access to Forms Services HTTP endpoints so they are reachable only from trusted networks or via VPN, and verify that Forms runtime servlets are not directly internet-exposed. Review HTTP access logs for anomalous unauthenticated requests to Forms endpoints and monitor affected servers for signs of compromise.
| Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode) | 12.2.1.19.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.