Junglewise Threat Intelligence

CVE-2026-83099: Oracle Forms unauthenticated remote code execution

CVE-2026-83099 · Severity: critical · CVSS 10 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a component of Oracle Fusion Middleware used to build and deploy enterprise business applications. This critical vulnerability allows unauthenticated attackers to gain complete control over Oracle Forms systems via network access, potentially compromising sensitive business data and disrupting critical operations across the organization.

Technical details

This is an unauthenticated remote code execution vulnerability in Oracle Forms (component: Forms Services, C/S, Charmode) affecting versions 12.2.1.19.0 and 14.1.2.0.0. The vulnerability has a network attack vector with no authentication required and no user interaction needed, making it trivially exploitable. Successful exploitation results in complete system compromise with full confidentiality, integrity, and availability impact. While the vulnerability resides in Oracle Forms, the scope extends to impact other products in the Fusion Middleware environment.

Affected products

  • Oracle Forms 12.2.1.19.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References