ZeroHour

CVE-2026-83108

moderate

Unauthenticated Remote Takeover in Oracle Forms (Fusion Middleware)

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

A critical vulnerability (CVSS 9.8) in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware, allows an unauthenticated remote attacker with HTTP network access to fully compromise the Oracle Forms installation. The flaw is rated as easily exploitable, requires no privileges, user interaction, or authentication, and a successful attack results in complete takeover of Oracle Forms with high impact to confidentiality, integrity, and availability — consistent with full server compromise such as code execution. Affected versions are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0, which are common in on-premises enterprise deployments that expose Forms servlets to internal or internet-facing users. No public proof-of-concept is known and the issue does not appear in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently evidenced.

What to do: Apply the Oracle Critical Patch Update that remedies this flaw to all Oracle Forms installations running 12.2.1.19.0 or 14.1.2.0.0 as soon as Oracle releases the applicable patch. In the interim, restrict network access to Forms Services HTTP endpoints so they are reachable only through a VPN or authenticated reverse proxy rather than directly from the internet. Review web server and Forms servlet logs for unexplained unauthenticated HTTP requests or anomalous session activity, and monitor Oracle's security alerts for updates on exploitation.

Affected
Oracle Forms (Oracle Fusion Middleware, Forms Services, C/S, Charmode component)12.2.1.19.0
Oracle Forms (Oracle Fusion Middleware, Forms Services, C/S, Charmode component)14.1.2.0.0
Estimated exposure
moderatelikely low thousands of internet-reachable Oracle Forms servers, plus additional intranet-only enterprise deployments — Oracle Forms is deployed almost exclusively in on-premises enterprise middleware environments, and public internet-wide scan services typically show a few thousand exposed Forms/Reports endpoints, with most instances restricted to internal…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.