Description
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Oracle Forms by Oracle Fusion Middleware has a vulnerability in the Forms Services component that can be exploited by an attacker who has network access over HTTP. The flaw is easily exploitable and allows the attacker to gain high privileges, which can lead to a full takeover of the Oracle Forms application. Successful exploitation would compromise confidentiality, integrity, and availability of the affected system, and the impact can extend to other dependent products, as the scope is changed.

Affected Systems

The affected product is Oracle Forms from Oracle Corporation. Versions 12.2.1.19.0 and 14.1.2.0.0 are impacted. The vulnerability is specific to the Forms Services, C/S, Charmode component of Oracle Fusion Middleware.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity, but the EPSS score of less than 1% suggests that, at the time of this analysis, the likelihood of real‑world exploitation is low. The vulnerability is not listed in CISA KEV. The likely attack vector involves sending a crafted HTTP request to the Form Services endpoint, exploiting the code path that fails to enforce proper access control and allows the attacker to elevate privileges and execute arbitrary code.

Generated by OpenCVE AI on September 20, 2026 at 09:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the most recent Oracle Forms patch for versions 12.2.1.19.0 and 14.1.2.0.0, as detailed in the Oracle security advisory.
  • Limit network exposure by restricting HTTP access to Oracle Forms to trusted IP ranges or by placing the application behind a firewall and applying strict ACLs.
  • Isolate the application in a separate network segment and enable a web application firewall to detect and block malicious requests to the Forms Services component.

Generated by OpenCVE AI on September 20, 2026 at 09:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title High Privilege Oracle Forms Remote Code Execution via HTTP

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title High Privilege Oracle Forms Remote Code Execution via HTTP
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle forms
CPEs cpe:2.3:a:oracle:forms:12.2.1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle forms
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:19:40.322Z

Reserved: 2026-08-31T15:40:57.340Z

Link: CVE-2026-83103

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:55.151Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:20.440

Modified: 2026-09-17T16:18:03.090

Link: CVE-2026-83103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T09:45:17Z

Weaknesses