Junglewise Threat Intelligence

CVE-2026-83105: Oracle Forms remote code execution in HTTP listener

CVE-2026-83105 · Severity: critical · CVSS 9 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a web-based application development platform used to build business applications accessed via HTTP. This vulnerability allows an unauthenticated attacker to remotely execute code and completely compromise the Forms server and potentially connected systems, affecting confidentiality, integrity, and availability of critical business applications.

Technical details

This is a difficult-to-exploit remote code execution vulnerability in the Forms Services HTTP listener (Charmode component) that requires no authentication and no user interaction. The vulnerability resides in the C/S (client-server) Forms Services component and can be exploited via HTTP network access. Successful exploitation results in complete system compromise with scope change, meaning the impact extends beyond the Forms product itself to other systems. The vulnerability affects Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0. No patch availability information is currently available from the truncated reference materials.

Affected products

  • Oracle Forms 12.2.1.19.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References