Description
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the Forms Services, C/S, Charmode component of Oracle Forms within Oracle Fusion Middleware. An unauthenticated attacker who can reach the HTTP endpoint can exploit the flaw, potentially taking full control of the application. Because the flaw can be triggered without credentials, the attacker can compromise confidentiality, integrity, and availability, effectively achieving remote code execution or takeover of Oracle Forms.

Affected Systems

Affected are Oracle Forms 12.2.1.19.0 and 14.1.2.0.0, both supported versions of Oracle Fusion Middleware. Systems running either of these builds without the published fix should be considered at risk. Administration should review deployment inventories to identify any instances of these versions.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 indicates high severity, and the EPSS score of less than 1% shows a low current exploitation probability. The flaw is not listed in CISA’s KEV catalog. Attackers only need network-level HTTP access to the Forms service, no user interaction or privileged credentials. Given the high impact and the straightforward attack vector, the risk remains high and remediation should be prioritized.

Generated by OpenCVE AI on September 20, 2026 at 11:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade to a version that contains the fix for CVE-2026-83101.
  • Restrict network access to the Forms service so that only trusted hosts can reach the HTTP endpoint, using firewalls or VPN controls.
  • Configure and enforce authentication for the Forms Services component to prevent unauthenticated access, and monitor logs for anomalous HTTP requests.

Generated by OpenCVE AI on September 20, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Oracle Forms Takeover

Sun, 20 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Oracle Forms Remote Takeover via HTTP
Weaknesses CWE-287

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Oracle Forms Remote Takeover via HTTP
Weaknesses CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle forms
CPEs cpe:2.3:a:oracle:forms:12.2.1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle forms
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:19:54.809Z

Reserved: 2026-08-31T15:40:57.339Z

Link: CVE-2026-83101

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:57.425Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:20.223

Modified: 2026-09-17T16:18:02.800

Link: CVE-2026-83101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:30:17Z

Weaknesses