ZeroHour

CVE-2026-83099

moderate

Unauthenticated HTTP Takeover of Oracle Forms in Fusion Middleware (CVSS 10.0)

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83099 is a critical (CVSS 3.1 base score 10.0) unauthenticated vulnerability in the Forms Services client/server and character-mode components of Oracle Forms, part of Oracle Fusion Middleware. It is triggered remotely over HTTP by an attacker with no credentials and no user interaction, and successful exploitation results in a complete takeover of Oracle Forms with full impact to confidentiality, integrity, and availability. The CVSS vector includes a scope change (S:C), meaning attacks against the vulnerable Forms component can also significantly impact additional products on the compromised host. Affected deployments are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0. No public proof of concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83099 to all Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 installations as an emergency change, prioritizing any Forms Services endpoints reachable over the network. Remove internet exposure for Forms servlets and restrict access to trusted networks or VPN, and place the service behind an authenticating reverse proxy where possible. Review HTTP access logs for unauthenticated requests to Forms Services endpoints and watch for anomalous process or file activity on Forms hosts, since the scope change means adjacent products on the same server may be impacted after compromise.

Affected
Oracle Fusion Middleware / Oracle Forms (Forms Services, C/S, Charmode)12.2.1.19.0, 14.1.2.0.0
Estimated exposure
moderate≈ low thousands of internet-exposed Oracle Forms endpoints, plus a larger unknown population of internal enterprise deployments — Oracle Forms is a legacy enterprise middleware product whose Forms servlets typically appear in internet-wide scans (e.g., Shodan/FOFA-style data) at levels of a few thousand exposed hosts, while most instances sit on corporate intranets…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.