ZeroHour

CVE-2026-83096

moderate

Low-Privilege Data Tampering Flaw in Oracle Forms Services 12.2.1.19.0 / 14.1.2.0.0

CVSS 3.1
7.9 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83096 is a difficult-to-exploit vulnerability in the Forms Services (C/S, Charmode) component of Oracle Forms, part of Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. A low-privileged remote attacker with HTTP access to the Forms Services endpoint can trigger the flaw, but a successful attack additionally requires interaction from a victim user other than the attacker (per the CVSS vector UI:R), suggesting a social-engineering or request-forgery style trigger. If exploited, the attacker gains unauthorized creation, deletion, or modification of critical data or all Oracle Forms-accessible data, unauthorized read access to that data, and a partial denial of service against Oracle Forms; the scope change (S:C) means successful attacks can also significantly impact products beyond Oracle Forms itself. Affected parties are enterprises running the listed Forms releases, typically internet- or intranet-facing legacy business applications. No public proof of concept exists and the flaw is not on the CISA Known Exploited Vulnerabilities catalog, so exploitation is presumed none known at this time.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83096 to versions beyond 12.2.1.19.0 and 14.1.2.0.0 as soon as it is available for your release line. Restrict network access to Forms Services endpoints (VPN/IP allowlisting) and enforce strong authentication and least-privilege accounts for low-privilege Forms users. Because exploitation requires victim interaction, brief users on suspicious links/requests, and audit Forms-accessible data for unauthorized creation, modification, or deletion.

Affected
Oracle Fusion Middleware — Oracle Forms (Forms Services, C/S, Charmode)12.2.1.19.0, 14.1.2.0.0
Estimated exposure
moderate≈ several thousand internet-exposed Oracle Forms endpoints, plus a larger unknown population of intranet deployments (order of 10,000 systems total) — Oracle Forms is a legacy enterprise middleware product with a finite install base; public internet scans (Shodan/Censys) have historically shown low-thousands of exposed Forms servlet endpoints, and most deployments sit behind corporate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as unauthorized access to critical data or complete access to all Oracle Forms accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Forms. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.