Executive brief
Oracle Forms is a development and deployment platform for enterprise business applications. A critical vulnerability in Forms Services allows an unauthenticated attacker to gain complete control over the Forms application and underlying system via the network, compromising confidentiality, integrity, and availability of all data and operations dependent on that Forms instance.
Technical details
The vulnerability exists in Oracle Forms Services (component: Forms Services, C/S, Charmode) and is easily exploitable without authentication. An attacker with network access via HTTP can craft a malicious request to achieve remote code execution and complete system compromise. The vulnerability affects Forms versions 12.2.1.19.0 and 14.1.2.0.0. The unauthenticated, network-accessible attack vector combined with a low complexity requirement makes this a critical risk to exposed Forms deployments. Oracle has issued patches for affected versions.
Affected products
- Oracle Forms 12.2.1.19.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed