ZeroHour

CVE-2026-83106

moderate

Low-Privilege Takeover Flaw in Oracle Forms Services 12.2.1.19.0 and 14.1.2.0.0

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83106 is a difficult-to-exploit vulnerability in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. A low-privileged (authenticated) attacker with network access via HTTP can trigger the flaw to fully compromise the Oracle Forms installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). In practice, this means an attacker who already holds a low-privilege account or session against a Forms endpoint could escalate to complete takeover of the Forms server. Organizations exposing Oracle Forms over HTTP to broader networks, or granting many users low-privilege Forms access, face the greatest risk. No public proof of concept is known and the CVE is not on CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.

What to do: Apply Oracle's latest Critical Patch Update bundle patch for Oracle Forms on both 12.2.1.19.0 and 14.1.2.0.0 as soon as it is available. Restrict HTTP access to Forms Services endpoints so only trusted users and networks can reach them, and audit which low-privilege Forms accounts exist and are actually needed. Review authentication and session logs on Forms servers for anomalous activity by low-privileged accounts, since exploitation requires valid but limited access.

Affected
Oracle Fusion Middleware - Oracle Forms (Forms Services, C/S, Charmode)12.2.1.19.0
Oracle Fusion Middleware - Oracle Forms (Forms Services, C/S, Charmode)14.1.2.0.0
Estimated exposure
moderate≈ few thousand internet-exposed Oracle Forms endpoints, plus a larger unseen internal enterprise install base — Oracle Forms is legacy on-premises enterprise middleware; public internet scan services typically show only a few thousand Forms/Reports servers reachable from the internet, with the majority deployed on internal corporate networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.