CVE-2026-83108
moderateUnauthenticated Remote Takeover in Oracle Forms (Fusion Middleware)
A critical vulnerability (CVSS 9.8) in the Forms Services, C/S, Charmode component of Oracle Forms, part of Oracle Fusion Middleware, allows an unauthenticated remote attacker with HTTP network access to fully compromise the Oracle Forms installation. The flaw is rated as easily exploitable, requires no privileges, user interaction, or authentication, and a successful attack results in complete takeover of Oracle Forms with high impact to confidentiality, integrity, and availability — consistent with full server compromise such as code execution. Affected versions are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0, which are common in on-premises enterprise deployments that expose Forms servlets to internal or internet-facing users. No public proof-of-concept is known and the issue does not appear in CISA's Known Exploited Vulnerabilities catalog, so exploitation in the wild is not currently evidenced.
What to do: Apply the Oracle Critical Patch Update that remedies this flaw to all Oracle Forms installations running 12.2.1.19.0 or 14.1.2.0.0 as soon as Oracle releases the applicable patch. In the interim, restrict network access to Forms Services HTTP endpoints so they are reachable only through a VPN or authenticated reverse proxy rather than directly from the internet. Review web server and Forms servlet logs for unexplained unauthenticated HTTP requests or anomalous session activity, and monitor Oracle's security alerts for updates on exploitation.
| Oracle Forms (Oracle Fusion Middleware, Forms Services, C/S, Charmode component) | 12.2.1.19.0 |
| Oracle Forms (Oracle Fusion Middleware, Forms Services, C/S, Charmode component) | 14.1.2.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.