Description
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Confidential Data
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an authorization bypass in Oracle Forms that allows an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data or all data accessible through Oracle Forms. It is an access control flaw (CWE-284) that can expose confidential information and potentially affect other products that rely on Forms services.

Affected Systems

Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0 are affected. The flaw resides in the Forms Services, client/server and Charmode components of Oracle Fusion Middleware.

Risk and Exploitability

The CVSS 3.1 base score of 8.6 indicates high severity, with a low exploitation probability (EPSS < 1%) and it is not listed in the CISA KEV catalog. The likely attack vector is over the network via standard HTTP traffic; the flaw can be exploited without authentication, making it easily exploitable to compromise the Forms deployment and any downstream applications that use its data.

Generated by OpenCVE AI on September 20, 2026 at 09:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Forms security patch that fixes CVE-2026-83093.
  • Restrict HTTP access to the Oracle Forms service to trusted IP addresses or internal networks using firewall rules or reverse-proxy configuration.
  • Enable detailed logging of HTTP requests to Oracle Forms and review logs for suspicious activity.

Generated by OpenCVE AI on September 20, 2026 at 09:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Remote Authorization Bypass in Oracle Forms

Thu, 17 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Remote Authorization Bypass in Oracle Forms

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle forms
CPEs cpe:2.3:a:oracle:forms:12.2.1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle forms
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:58:13.613Z

Reserved: 2026-08-31T15:40:57.339Z

Link: CVE-2026-83093

cve-icon Vulnrichment

Updated: 2026-09-16T17:52:12.773Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:19.203

Modified: 2026-09-23T15:25:51.457

Link: CVE-2026-83093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:00:09Z

Weaknesses