Junglewise Threat Intelligence

CVE-2026-83095: Oracle Forms unauthenticated remote code execution

CVE-2026-83095 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a widely-deployed enterprise application development framework used to build mission-critical business applications. This vulnerability allows an unauthenticated attacker on the network to take complete control of Oracle Forms instances without any credentials or user interaction, potentially compromising sensitive business data and halting critical operations.

Technical details

This vulnerability in Oracle Forms Services (C/S, Charmode component) allows unauthenticated remote attackers to compromise the application via HTTP. The attack requires only network access and no authentication or user interaction; the low complexity (AC:L) indicates the exploitation method is straightforward. Successful exploitation results in complete system compromise with impacts to confidentiality, integrity, and availability—equivalent to remote code execution or full takeover of the Forms application. Affected versions are 12.2.1.19.0 and 14.1.2.0.0 of Oracle Fusion Middleware Forms product. Oracle has issued a security advisory; patch or workaround details should be consulted from the official Oracle security bulletin.

Affected products

  • Oracle Forms 12.2.1.19.0 and 14.1.2.0.0

Timeline

  • 2026-09-15: published: Vulnerability advisory published

References