Description
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification
Action: Immediate Patch
AI Analysis

Impact

This vulnerability resides in the Forms Services component of Oracle Forms within Oracle Fusion Middleware, specifically affecting versions 12.2.1.19.0 and 14.1.2.0.0. An unauthenticated attacker with HTTP network access can exploit a difficult‑to‑exploit flaw that grants the ability to create, delete, or modify critical data accessed through Oracle Forms. The impact is a compromise of confidentiality and integrity of all data exposed by the affected instances, as indicated by the CVSS 3.1 Base Score of 7.4.

Affected Systems

Oracle Forms, a product of Oracle Corporation distributed as part of Oracle Fusion Middleware, contains the vulnerable Forms Services, Client/Server, Charmode subsystem. Versions 12.2.1.19.0 and 14.1.2.0.0 are affected and all applications hosted on these instances are at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.4, signaling a moderate‑to‑high risk level because of the potential for significant confidentiality and integrity loss. However, the EPSS score is less than 1 %, suggesting that public exploitation cases are unlikely at present. The CVE is not listed in the CISA KEV catalog, further indicating low exploitation probability. Attackers would need to send unauthenticated HTTP requests to the Forms service; once the condition is met, they could write arbitrary data, creating, deleting, or modifying sensitive records.

Generated by OpenCVE AI on September 18, 2026 at 20:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the official Oracle Forms security patch or upgrade to a release that includes the fix
  • Configure Oracle Forms to enforce authentication for all HTTP traffic and disable unauthenticated access
  • Restrict inbound network traffic to the Oracle Forms HTTP port to trusted hosts or networks, and monitor logs for unauthorized write attempts
  • Apply web application firewall rules that block suspicious HTTP requests to the Forms service

Generated by OpenCVE AI on September 18, 2026 at 20:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Control of Oracle Forms Data

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Control of Oracle Forms Data
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle forms
CPEs cpe:2.3:a:oracle:forms:12.2.1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle forms
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:19:47.005Z

Reserved: 2026-08-31T15:40:57.340Z

Link: CVE-2026-83102

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:56.449Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:20.333

Modified: 2026-09-17T16:18:02.940

Link: CVE-2026-83102

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:00:15Z

Weaknesses