Junglewise Threat Intelligence

CVE-2026-83100: Oracle Forms remote code execution in Forms Services

CVE-2026-83100 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a server-side application development framework used to build business applications within Oracle Fusion Middleware. An unauthenticated network-accessible vulnerability in the Forms Services component allows attackers to gain complete control over the Oracle Forms instance, compromising confidentiality, integrity, and availability of the application and its data.

Technical details

This vulnerability affects Oracle Forms' Forms Services component (C/S, Charmode) and allows an unauthenticated attacker with network access via HTTP to achieve remote code execution or complete system compromise. The vulnerability is easily exploitable and requires no special preconditions—no authentication, user interaction, or complex setup is needed. Successful exploitation results in full takeover of the Oracle Forms application, affecting all three security pillars: confidentiality, integrity, and availability. No patch information is currently available in the advisory.

Affected products

  • Oracle Forms 12.2.1.19.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References