Junglewise Threat Intelligence

CVE-2026-83093: Oracle Forms unauthorized data access via HTTP

CVE-2026-83093 · Severity: high · CVSS 8.6 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a web-based application development platform used to build enterprise business applications within Oracle Fusion Middleware. An unauthenticated attacker can access the Forms Services component over the network without requiring credentials, gaining unauthorized access to sensitive business data or complete control over all Forms data accessible through the system. This vulnerability bypasses authentication controls entirely and could expose customer information, financial data, or proprietary business logic to external attackers.

Technical details

This is an authentication bypass vulnerability in Oracle Forms Services (Charmode and C/S variants) that allows unauthenticated network access via HTTP. The vulnerability has a network attack vector with no authentication required and no user interaction, indicating a direct flaw in the HTTP request handling or session management within Forms Services. Successful exploitation results in unauthorized confidentiality impact—attackers gain read access to critical data across all Oracle Forms instances accessible through the affected component. The vulnerability affects Forms versions 12.2.1.19.0 and 14.1.2.0.0; patch availability should be verified against Oracle's security advisory.

Affected products

  • Oracle Forms 12.2.1.19.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References