CVE-2026-83099
moderateUnauthenticated HTTP Takeover of Oracle Forms in Fusion Middleware (CVSS 10.0)
CVE-2026-83099 is a critical (CVSS 3.1 base score 10.0) unauthenticated vulnerability in the Forms Services client/server and character-mode components of Oracle Forms, part of Oracle Fusion Middleware. It is triggered remotely over HTTP by an attacker with no credentials and no user interaction, and successful exploitation results in a complete takeover of Oracle Forms with full impact to confidentiality, integrity, and availability. The CVSS vector includes a scope change (S:C), meaning attacks against the vulnerable Forms component can also significantly impact additional products on the compromised host. Affected deployments are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0. No public proof of concept exists, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83099 to all Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 installations as an emergency change, prioritizing any Forms Services endpoints reachable over the network. Remove internet exposure for Forms servlets and restrict access to trusted networks or VPN, and place the service behind an authenticating reverse proxy where possible. Review HTTP access logs for unauthenticated requests to Forms Services endpoints and watch for anomalous process or file activity on Forms hosts, since the scope change means adjacent products on the same server may be impacted after compromise.
| Oracle Fusion Middleware / Oracle Forms (Forms Services, C/S, Charmode) | 12.2.1.19.0, 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.