ZeroHour

CVE-2026-83101

moderate

Unauthenticated Takeover Flaw in Oracle Forms (Fusion Middleware)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

A difficult-to-exploit vulnerability in the Forms Services C/S Charmode component of Oracle Forms allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in a complete takeover of Oracle Forms, with high impacts to confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). Organizations running Oracle Fusion Middleware Forms releases 12.2.1.19.0 or 14.1.2.0.0 are affected. The high attack complexity means reliable exploitation is non-trivial, and no public proof-of-concept or confirmed in-the-wild exploitation has been reported. The flaw was assigned and patched by Oracle, most plausibly via a quarterly Critical Patch Update.

What to do: Apply the Oracle Critical Patch Update that addresses this CVE to Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 as soon as your patching cycle allows, since no workaround is indicated. Restrict network access to Forms Services endpoints so they are not reachable over unauthenticated HTTP from the internet, enforce TLS, and use firewall allowlists for known clients. Review Forms Services logs for anomalous unauthenticated requests and confirm no unauthorized configuration changes or account activity has occurred.

Affected
Oracle Forms (Oracle Fusion Middleware, Forms Services C/S Charmode component)12.2.1.19.0
Oracle Forms (Oracle Fusion Middleware, Forms Services C/S Charmode component)14.1.2.0.0
Estimated exposure
moderate≈ low thousands of internet-exposed Oracle Forms endpoints; tens of thousands of on-premises Fusion Middleware deployments overall (estimate) — Oracle Forms is enterprise middleware typically deployed inside corporate networks, with public scan data historically showing only a few thousand internet-reachable Forms/Reports endpoints out of a larger base of on-premises Oracle…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.