Description
Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

This vulnerability in Oracle Forms allows an attacker with network access to a compromised HTTP interface to elevate privileges and take full control of the application. The flaw results in complete loss of confidentiality, integrity and availability for the affected instance. The disclosed CVSS vector indicates a network attack that can be performed with low effort and high privilege impact, resulting in a 9.1 base score.

Affected Systems

Oracle Forms product of Oracle Fusion Middleware, versions 12.2.1.19.0 and 14.1.2.0.0 are affected. The vulnerability exists in the Forms Services, Client/Server, Charmode components. These versions are currently supported under Oracle’s release schedule.

Risk and Exploitability

The CVSS score of 9.1 marks this as a critical issue, and although the EPSS score is presently less than 1%, the fact that it is exploitable over HTTP makes it a priority for defense. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, but the potential for a full takeover means it could be a high‑profile target should an attacker discover it. Based on the description, the likely attack vector is a network‑based HTTP request that bypasses normal authentication checks, allowing an attacker to obtain high‑privilege control of the Forms instance.

Generated by OpenCVE AI on September 20, 2026 at 11:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Review the Oracle security alert (https://www.oracle.com/security-alerts/cspusep2026.html) for the latest guidance and check for any available patches.
  • Restrict HTTP access to the Oracle Forms service to trusted networks or clients by applying firewall or reverse proxy rules.
  • Monitor Forms service logs for unusual or unauthorized HTTP requests and investigate any anomalies.
  • Apply any official Oracle Forms security updates as they are released; ensure the affected versions (12.2.1.19.0 and 14.1.2.0.0) are updated.

Generated by OpenCVE AI on September 20, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Oracle Forms Remote Privilege Escalation via HTTP

Sun, 20 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation Exploitable via HTTP in Oracle Forms
Weaknesses CWE-269

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation Exploitable via HTTP in Oracle Forms
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle forms
CPEs cpe:2.3:a:oracle:forms:12.2.1.19.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:forms:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle forms
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:19:14.331Z

Reserved: 2026-08-31T15:40:57.340Z

Link: CVE-2026-83107

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:51.462Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:20.893

Modified: 2026-09-17T16:18:03.637

Link: CVE-2026-83107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:30:17Z

Weaknesses