Junglewise Threat Intelligence

CVE-2026-83094: Oracle Forms unauthenticated remote code execution

CVE-2026-83094 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a development and deployment platform for enterprise business applications. A critical vulnerability in Forms Services allows an unauthenticated attacker to gain complete control over the Forms application and underlying system via the network, compromising confidentiality, integrity, and availability of all data and operations dependent on that Forms instance.

Technical details

The vulnerability exists in Oracle Forms Services (component: Forms Services, C/S, Charmode) and is easily exploitable without authentication. An attacker with network access via HTTP can craft a malicious request to achieve remote code execution and complete system compromise. The vulnerability affects Forms versions 12.2.1.19.0 and 14.1.2.0.0. The unauthenticated, network-accessible attack vector combined with a low complexity requirement makes this a critical risk to exposed Forms deployments. Oracle has issued patches for affected versions.

Affected products

  • Oracle Forms 12.2.1.19.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References