Junglewise Threat Intelligence

CVE-2026-83098: Oracle Forms unauthenticated remote compromise in Forms Services

CVE-2026-83098 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a widely-used enterprise application development platform used to build business-critical applications. This vulnerability allows an unauthenticated attacker to remotely compromise Oracle Forms systems over the network without any credentials or user interaction, potentially gaining full control of the affected application and the data it processes or maintains.

Technical details

This is a critical remote code execution vulnerability in Oracle Forms Services (C/S, Charmode component) that can be exploited without authentication. The vulnerability is easily exploitable through HTTP network access with no prerequisites or user interaction required. Successful exploitation results in complete compromise of the Oracle Forms system, affecting confidentiality, integrity, and availability. Affected versions include 12.2.1.19.0 and 14.1.2.0.0; patches should be obtained from Oracle's official security advisories.

Affected products

  • Oracle Forms 12.2.1.19.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References