CVE-2026-83100
moderateUnauthenticated HTTP Takeover in Oracle Forms (Fusion Middleware), CVSS 9.8
CVE-2026-83100 is a critical (CVSS 9.8) flaw in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware. An unauthenticated attacker with network access via HTTP can exploit it easily to fully compromise the Oracle Forms installation, with high impact on confidentiality, integrity, and availability — effectively a takeover of the service. Affected supported versions are 12.2.1.19.0 and 14.1.2.0.0. Organizations running internet-facing or internally reachable Forms endpoints are at risk of server compromise. No public proof-of-concept is known, the flaw is not on CISA's KEV list, and no in-the-wild exploitation has been reported, but the unauthenticated, low-complexity nature makes it a prime target once details circulate.
What to do: Apply Oracle's latest Critical Patch Update for Fusion Middleware to remediate 12.2.1.19.0 and 14.1.2.0.0 as soon as it is available for your environment. Until patched, restrict network access to Forms servlet endpoints (firewall allow-lists, VPN, or reverse proxy with authentication) and avoid exposing Forms services directly to the internet. Review HTTP access logs around Forms endpoints for anomalous unauthenticated requests as an indicator of attempted exploitation.
| Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode) | 12.2.1.19.0 |
| Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.