Executive brief
Oracle Forms is a widely-used enterprise application development platform used to build business-critical applications. This vulnerability allows an unauthenticated attacker to remotely compromise Oracle Forms systems over the network without any credentials or user interaction, potentially gaining full control of the affected application and the data it processes or maintains.
Technical details
This is a critical remote code execution vulnerability in Oracle Forms Services (C/S, Charmode component) that can be exploited without authentication. The vulnerability is easily exploitable through HTTP network access with no prerequisites or user interaction required. Successful exploitation results in complete compromise of the Oracle Forms system, affecting confidentiality, integrity, and availability. Affected versions include 12.2.1.19.0 and 14.1.2.0.0; patches should be obtained from Oracle's official security advisories.
Affected products
- Oracle Forms 12.2.1.19.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed