Description
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Takeover
Action: Immediate Patch
AI Analysis

Impact

The flaw in Oracle Forms Services, specifically within the client/server and Charmode components, allows an attacker with low privileged network access to take complete control of the Forms service. By leveraging this, the attacker can compromise the confidentiality, integrity, and availability of the application. The weakness relates to improper authorization (CWE-284).

Affected Systems

Oracle Forms product from Oracle Corporation, affecting versions 12.2.1.19.0 and 14.1.2.0.0 which are part of the Oracle Fusion Middleware stack.

Risk and Exploitability

The vulnerability carries a CVSS v3.1 base score of 7.5, indicating high impact if exploited. The EPSS score is less than 1 %, suggesting a low probability of exploitation in the short term, and it is not listed in CISA’s KEV catalog. The attack vector, inferred from the description, requires only network access to the Forms HTTP service and does not require elevated privileges, making it potentially reachable from remote locations.

Generated by OpenCVE AI on September 20, 2026 at 11:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Forms patch or upgrade to a non‑affected version, following Oracle’s security update procedures.
  • Restrict HTTP access to the Forms service by configuring firewalls or access control lists to limit traffic to trusted IP ranges.
  • Review and enforce strict authentication and authorization settings within Forms to ensure users have only the permissions necessary for their roles.

Generated by OpenCVE AI on September 20, 2026 at 11:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Oracle Forms Improper Authorization Allows Remote Takeover

Sun, 20 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle Forms via HTTP in Oracle Fusion Middleware
Weaknesses CWE-287

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover of Oracle Forms via HTTP in Oracle Fusion Middleware
Weaknesses CWE-284
CWE-287

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle forms
CPEs cpe:2.3:a:oracle:forms:12.2.1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle forms
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:19:22.804Z

Reserved: 2026-08-31T15:40:57.340Z

Link: CVE-2026-83106

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:52.533Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:20.783

Modified: 2026-09-17T16:18:03.400

Link: CVE-2026-83106

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:45:12Z

Weaknesses