Executive brief
Oracle Forms is a widely used enterprise application development platform that allows organizations to build and deploy business applications. This vulnerability allows an unauthenticated attacker with network access to bypass security controls and gain unauthorized access to sensitive data, potentially enabling the modification or deletion of critical business information. The attack requires no user interaction and can be exploited remotely over the network.
Technical details
This is an unauthenticated remote code execution or privilege escalation vulnerability in the Oracle Forms Services component (specifically the C/S Charmode interface). The vulnerability exists in supported versions 12.2.1.19.0 and 14.1.2.0.0 and can be exploited via TCP network access without requiring authentication, user interaction, or special privileges. A successful attack allows an attacker to create, modify, or delete critical data, as well as read all data accessible through Oracle Forms. The vulnerability affects both confidentiality and integrity of Oracle Forms systems.
Affected products
- Oracle Forms 12.2.1.19.0, 14.1.2.0.0
Timeline
- 2026-09-15: disclosed