Executive brief
Oracle Forms is a web-based business application development tool used to build and deploy enterprise applications within Oracle Fusion Middleware. This vulnerability allows a low-privileged attacker with network access to bypass authorization controls and gain unauthorized access to create, modify, or delete critical business data, as well as potentially disrupt service availability. The attack requires user interaction and could impact other integrated systems sharing the same data repositories.
Technical details
This is a privilege escalation vulnerability in Oracle Forms Services (component: Forms Services, C/S, Charmode) affecting versions 12.2.1.19.0 and 14.1.2.0.0. The vulnerability is difficult to exploit and requires low-privilege authentication plus user interaction (social engineering or clickable link) to trigger. Attack vector is network-based via HTTP. Successful exploitation allows unauthorized read, write, and delete operations on critical data accessible through Forms, as well as partial denial-of-service conditions. The scope is marked as changed, indicating that the vulnerability may affect other Oracle Fusion Middleware products and downstream systems. Patch status is not confirmed in the advisory.
Affected products
- Oracle Forms 12.2.1.19.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed