ZeroHour

CVE-2026-83102

moderate

Unauthenticated Data Manipulation Flaw in Oracle Forms Services (Charmode)

CVSS 3.1
7.4 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83102 is a difficult-to-exploit vulnerability in the Forms Services (C/S, Charmode) component of Oracle Forms, part of Oracle Fusion Middleware. An unauthenticated remote attacker with network access via HTTP can trigger the flaw, and successful attacks allow unauthorized creation, deletion, or modification of critical data — or of all Oracle Forms-accessible data — as well as unauthorized read access to that data. The issue is rated CVSS 3.1 7.4 (high), with high confidentiality and integrity impact but no availability impact, and it affects Oracle Forms 12.2.1.19.0 and 14.1.2.0.0. Organizations exposing Oracle Forms endpoints over HTTP, particularly internet-facing Forms servlets for legacy enterprise applications, are the most relevant targets. No public proof of concept is known, the issue is not in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been reported.

What to do: Apply the Oracle Critical Patch Update that addresses CVE-2026-83102 to Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 deployments. Restrict HTTP access to Forms Services endpoints so they are reachable only from trusted networks or via authenticated reverse proxy, and audit Forms-accessible data for unauthorized creation, deletion, or modification. Inventory internet-facing Oracle Forms servlets and prioritize patching those, since the flaw is exploitable without authentication over HTTP.

Affected
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)12.2.1.19.0
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)14.1.2.0.0
Estimated exposure
moderate≈ low thousands of internet-exposed Oracle Forms endpoints, plus a larger unknown population of internal enterprise deployments — Oracle Forms is legacy enterprise middleware, and public internet scans (e.g., Shodan/Censys) have historically shown only a few thousand exposed Forms servlets, so exposure is plausibly in the 1k–10k range for internet-facing systems with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.