CVE-2026-83107
moderatePrivileged HTTP Takeover Flaw in Oracle Forms (Fusion Middleware)
CVE-2026-83107 is a critical (CVSS 9.1) vulnerability in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware, affecting versions 12.2.1.19.0 and 14.1.2.0.0. It is easily exploitable by a high-privileged attacker who has network access to the Forms server via HTTP, requiring no user interaction. Because of a scope change, successful attacks on Oracle Forms can significantly impact additional products beyond the vulnerable component. A successful exploit results in complete takeover of Oracle Forms with high impacts to confidentiality, integrity, and availability. No public proof-of-concept exists and the flaw is not in CISA's Known Exploited Vulnerabilities catalog, so exploitation is not currently observed.
What to do: Apply the Oracle Critical Patch Update that addresses this flaw for Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 as soon as it is available. Restrict HTTP access to Forms Services endpoints (for example the Forms servlet) using VPN or IP allowlisting so only trusted high-privileged users can reach them, and audit those accounts for signs of misuse. Review logs for suspicious privileged activity and rotate credentials for Forms administrator and application accounts.
| Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode) | 12.2.1.19.0 |
| Oracle Forms (Oracle Fusion Middleware, component: Forms Services, C/S, Charmode) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.