CVE-2026-83106
moderateLow-Privilege Takeover Flaw in Oracle Forms Services 12.2.1.19.0 and 14.1.2.0.0
CVE-2026-83106 is a difficult-to-exploit vulnerability in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. A low-privileged (authenticated) attacker with network access via HTTP can trigger the flaw to fully compromise the Oracle Forms installation, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.5). In practice, this means an attacker who already holds a low-privilege account or session against a Forms endpoint could escalate to complete takeover of the Forms server. Organizations exposing Oracle Forms over HTTP to broader networks, or granting many users low-privilege Forms access, face the greatest risk. No public proof of concept is known and the CVE is not on CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply Oracle's latest Critical Patch Update bundle patch for Oracle Forms on both 12.2.1.19.0 and 14.1.2.0.0 as soon as it is available. Restrict HTTP access to Forms Services endpoints so only trusted users and networks can reach them, and audit which low-privilege Forms accounts exist and are actually needed. Review authentication and session logs on Forms servers for anomalous activity by low-privileged accounts, since exploitation requires valid but limited access.
| Oracle Fusion Middleware - Oracle Forms (Forms Services, C/S, Charmode) | 12.2.1.19.0 |
| Oracle Fusion Middleware - Oracle Forms (Forms Services, C/S, Charmode) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.