ZeroHour

CVE-2026-83098

moderate

Unauthenticated HTTP Takeover Flaw in Oracle Forms (Fusion Middleware)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83098 is a critical (CVSS 9.8) vulnerability in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware. An unauthenticated remote attacker with network access via HTTP can exploit it easily, without any privileges or user interaction, and fully compromise the Oracle Forms installation, with high impact on confidentiality, integrity, and availability — effectively a takeover of the affected Forms server. The supported affected versions are 12.2.1.19.0 and 14.1.2.0.0. Organizations exposing Oracle Forms servlet endpoints (common for legacy enterprise applications) are the primary at-risk population. No public proof-of-concept or confirmed in-the-wild exploitation is currently known, and the CVE is not on the CISA Known Exploited Vulnerabilities list.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83098 to systems running Oracle Forms 12.2.1.19.0 or 14.1.2.0.0. Until patched, restrict network access to Forms Services endpoints (VPN, allowlisting, or WAF rules) and ensure Forms servlets are not exposed directly to the internet. Review HTTP access logs for unauthenticated or anomalous requests to Forms Services URLs as an indicator of attempted exploitation.

Affected
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)12.2.1.19.0
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)14.1.2.0.0
Estimated exposure
moderate≈1,000–10,000 internet-exposed Oracle Forms endpoints, plus a larger unknown population of internal-only enterprise deployments — Oracle Forms is legacy enterprise middleware typically deployed on dedicated application servers; public internet scans (e.g., of /forms/frmservlet endpoints) historically show Forms services exposed in the low-thousands range, with many…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.