Description
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as unauthorized access to critical data or complete access to all Oracle Forms accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Forms. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L).
Published: 2026-09-15
Score: 7.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and partial denial of service
Action: Immediate patch
AI Analysis

Impact

A vulnerability in Oracle Forms allows a low‑privileged attacker who can reach the application over HTTP to gain unauthorized creation, deletion or modification of critical data, as well as unauthorized access to critical data and the ability to cause a partial denial of service. Successful exploitation requires human interaction from a user other than the attacker. The weakness is an access‑control misconfiguration that results in improper privilege management, enabling the attacker to bypass intended security boundaries.

Affected Systems

Affected applications include Oracle Forms 12.2.1.19.0 and 14.1.2.0.0, part of Oracle Corporation’s Oracle Fusion Middleware. These versions operate on the Forms Services, Client/Server, and Charmode components and are reachable over HTTP.

Risk and Exploitability

The CVSS v3.1 base score of 7.9 denotes moderate‑high severity, with confidentiality, integrity, and availability impacts. The EPSS score of less than 1% indicates a low probability of current exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the requirement for network access over HTTP and the need for a separate user to interact with the application mean that the attack vector is network‑based, with high exploitation complexity and low privileges. The scope change can affect other Oracle products, amplifying the potential damage to enterprise data.

Generated by OpenCVE AI on September 20, 2026 at 11:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Oracle Forms security patch that fixes the described access‑control misconfiguration.
  • Restrict network access to the Forms Services endpoint to trusted IP ranges and enforce HTTPS to protect in‑transit data.
  • Apply least‑privilege role‑based access control for all users who interact with Oracle Forms, ensuring that only authorized accounts can perform data‑creation, deletion, or modification operations.
  • Monitor access logs and network traffic for anomalous user interactions or repeated access attempts that could indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Title Low Privilege Network Attack Exploits Oracle Forms, Enabling Unauthorized Data Access and Partial Denial of Service
Weaknesses CWE-269

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Low Privilege Network Attack Exploits Oracle Forms, Enabling Unauthorized Data Access and Partial Denial of Service
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as unauthorized access to critical data or complete access to all Oracle Forms accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Forms. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle forms
CPEs cpe:2.3:a:oracle:forms:12.2.1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle forms
References
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:20:03.976Z

Reserved: 2026-08-31T15:40:57.339Z

Link: CVE-2026-83096

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:58.388Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:19.537

Modified: 2026-09-17T16:18:01.433

Link: CVE-2026-83096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:30:17Z

Weaknesses