Junglewise Threat Intelligence

CVE-2026-83097: Oracle Forms integrity and availability bypass in Forms Services

CVE-2026-83097 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a component of Oracle Fusion Middleware used to build and deploy enterprise business applications. A vulnerability in Forms Services allows a high-privileged attacker with network access to modify or delete critical application data and cause service outages. Organizations running affected versions should prioritize patching to restore data integrity and service availability.

Technical details

This vulnerability in Oracle Forms Services (HTTP-accessible component) allows an authenticated high-privileged attacker to manipulate or delete critical application data and trigger denial-of-service conditions. The attack requires network access but does not require user interaction. Exploitation can result in complete compromise of data integrity and service availability for Oracle Forms instances. Affected versions are 12.2.1.19.0 and 14.1.2.0.0. Oracle has released a security patch as part of their September 2026 Critical Patch Update.

Affected products

  • Oracle Forms 12.2.1.19.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References