Executive brief
Oracle Forms is a component of Oracle Fusion Middleware used to build enterprise database applications with web and desktop interfaces. An unauthenticated attacker on the network can exploit a difficult-to-exploit vulnerability in Forms Services via HTTP requests to achieve complete compromise of the Forms system, including unauthorized access to data and control of the application.
Technical details
This vulnerability affects Oracle Forms Services (character mode and client-server implementations) in versions 12.2.1.19.0 and 14.1.2.0.0. An unauthenticated remote attacker with network access can exploit this vulnerability via HTTP to achieve complete system compromise with high confidentiality, integrity, and availability impacts. The attack does not require user interaction and is difficult to exploit, suggesting a complex attack chain or specific preconditions. No details on the root cause or vulnerable component are currently available. Oracle has released security updates as part of the September 2026 Critical Patch Update.
Affected products
- Oracle Forms 12.2.1.19.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed