ZeroHour

CVE-2026-83105

moderate

Unauthenticated HTTP Takeover Flaw in Oracle Forms (Fusion Middleware)

CVSS 3.1
9.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83105 is a difficult-to-exploit but critical (CVSS 9.0) unauthenticated vulnerability in Oracle Forms, a legacy enterprise application component of Oracle Fusion Middleware, specifically in the Forms Services C/S Charmode component. An unauthenticated attacker with network access via HTTP who succeeds despite the high attack complexity can fully compromise Oracle Forms, and due to a scope change, successful attacks may significantly impact additional products beyond Forms itself. Successful exploitation results in a complete takeover of Oracle Forms with high impact to confidentiality, integrity, and availability. Affected installations run Oracle Forms versions 12.2.1.19.0 or 14.1.2.0.0. No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83105 to Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 installations as soon as possible, prioritizing any Forms Services endpoints reachable over the internet. Until patched, restrict HTTP access to Forms endpoints via firewall rules or reverse-proxy allowlisting, and consider placing Forms behind VPN/authentication. Review logs for anomalous unauthenticated requests to Forms Services endpoints and any unexpected process or configuration changes on Forms hosts, given the scope change means adjacent products may also be impacted.

Affected
Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode)
Estimated exposure
moderate≈1,000–10,000 internet-exposed Oracle Forms endpoints, plus a larger unknown number of intranet-only deployments — Oracle Forms is legacy enterprise middleware whose Forms servlet/listener endpoints appear in internet-wide scan data (Shodan/Censys-type sources) typically in the low thousands, with most additional deployments restricted to internal…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.