CVE-2026-83103
moderateAuthenticated Takeover Vulnerability in Oracle Forms (Fusion Middleware)
CVE-2026-83103 is a critical (CVSS 9.1) vulnerability in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. It is easily exploitable by a high-privileged attacker with network access via HTTP, who can use it to fully compromise the Oracle Forms installation (complete confidentiality, integrity, and availability impact). Because the flaw has a scope change (S:C), successful attacks may also significantly impact additional products beyond Oracle Forms itself. Organizations running the affected Forms versions on network-reachable servers are exposed to potential takeover by an insider or a compromised high-privilege account. No public proof of concept is known and the flaw is not on the CISA KEV list, so exploitation in the wild is not currently evidenced.
What to do: Apply the Oracle Critical Patch Update that remedies CVE-2026-83103 to systems running Oracle Forms 12.2.1.19.0 or 14.1.2.0.0 as soon as it is available for your release train, and verify no interim CPU patches are missed. Restrict HTTP access to Forms Services endpoints (e.g., /forms/frmservlet) to trusted networks or VPN, and tightly control and monitor high-privileged accounts, since exploitation requires elevated privileges. Review Forms server logs for unexpected privileged activity and assess whether adjacent Fusion Middleware components could be affected via the scope change.
| Oracle Fusion Middleware (Oracle Forms, component: Forms Services, C/S, Charmode) | 12.2.1.19.0 |
| Oracle Fusion Middleware (Oracle Forms, component: Forms Services, C/S, Charmode) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.