CVE-2026-83105
moderateUnauthenticated HTTP Takeover Flaw in Oracle Forms (Fusion Middleware)
CVE-2026-83105 is a difficult-to-exploit but critical (CVSS 9.0) unauthenticated vulnerability in Oracle Forms, a legacy enterprise application component of Oracle Fusion Middleware, specifically in the Forms Services C/S Charmode component. An unauthenticated attacker with network access via HTTP who succeeds despite the high attack complexity can fully compromise Oracle Forms, and due to a scope change, successful attacks may significantly impact additional products beyond Forms itself. Successful exploitation results in a complete takeover of Oracle Forms with high impact to confidentiality, integrity, and availability. Affected installations run Oracle Forms versions 12.2.1.19.0 or 14.1.2.0.0. No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported to date.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83105 to Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 installations as soon as possible, prioritizing any Forms Services endpoints reachable over the internet. Until patched, restrict HTTP access to Forms endpoints via firewall rules or reverse-proxy allowlisting, and consider placing Forms behind VPN/authentication. Review logs for anomalous unauthenticated requests to Forms Services endpoints and any unexpected process or configuration changes on Forms hosts, given the scope change means adjacent products may also be impacted.
| Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.