ZeroHour

CVE-2026-83100

moderate

Unauthenticated HTTP Takeover in Oracle Forms (Fusion Middleware), CVSS 9.8

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83100 is a critical (CVSS 9.8) flaw in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware. An unauthenticated attacker with network access via HTTP can exploit it easily to fully compromise the Oracle Forms installation, with high impact on confidentiality, integrity, and availability — effectively a takeover of the service. Affected supported versions are 12.2.1.19.0 and 14.1.2.0.0. Organizations running internet-facing or internally reachable Forms endpoints are at risk of server compromise. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported, but the unauthenticated, low-complexity nature makes it a prime target once details circulate.

What to do: Apply Oracle's latest Critical Patch Update for Fusion Middleware to remediate 12.2.1.19.0 and 14.1.2.0.0 as soon as it is available for your environment. Until patched, restrict network access to Forms servlet endpoints (firewall allow-lists, VPN, or reverse proxy with authentication) and avoid exposing Forms services directly to the internet. Review HTTP access logs around Forms endpoints for anomalous unauthenticated requests as an indicator of attempted exploitation.

Affected
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)12.2.1.19.0
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)14.1.2.0.0
Estimated exposure
moderateRoughly low thousands to ~10,000 internet-exposed Oracle Forms endpoints, plus a larger unknown set of internal enterprise deployments — Oracle Forms is enterprise middleware typically deployed by mid-to-large organizations; public internet scans historically show only low-thousands of directly exposed Forms/Reports endpoints, with most instances internal, so this is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.