CVE-2026-83096
moderateLow-Privilege Data Tampering Flaw in Oracle Forms Services 12.2.1.19.0 / 14.1.2.0.0
CVE-2026-83096 is a difficult-to-exploit vulnerability in the Forms Services (C/S, Charmode) component of Oracle Forms, part of Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. A low-privileged remote attacker with HTTP access to the Forms Services endpoint can trigger the flaw, but a successful attack additionally requires interaction from a victim user other than the attacker (per the CVSS vector UI:R), suggesting a social-engineering or request-forgery style trigger. If exploited, the attacker gains unauthorized creation, deletion, or modification of critical data or all Oracle Forms-accessible data, unauthorized read access to that data, and a partial denial of service against Oracle Forms; the scope change (S:C) means successful attacks can also significantly impact products beyond Oracle Forms itself. Affected parties are enterprises running the listed Forms releases, typically internet- or intranet-facing legacy business applications. No public proof of concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is presumed none known at this time.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83096 to versions beyond 12.2.1.19.0 and 14.1.2.0.0 as soon as it is available for your release line. Restrict network access to Forms Services endpoints (VPN/IP allowlisting) and enforce strong authentication and least-privilege accounts for low-privilege Forms users. Because exploitation requires victim interaction, brief users on suspicious links/requests, and audit Forms-accessible data for unauthorized creation, modification, or deletion.
| Oracle Fusion Middleware — Oracle Forms (Forms Services, C/S, Charmode) | 12.2.1.19.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as unauthorized access to critical data or complete access to all Oracle Forms accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Forms. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L
In the news0 stories
No ingested article mentions this CVE yet.