Junglewise Threat Intelligence

CVE-2026-83106: Oracle Forms remote code execution in Fusion Middleware

CVE-2026-83106 · Severity: high · CVSS 7.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a component of Oracle Fusion Middleware used for building enterprise business applications. A remote code execution vulnerability in Forms Services allows an authenticated attacker with low privileges to gain full control over the Forms system, potentially compromising sensitive business data and application availability.

Technical details

A difficult-to-exploit vulnerability exists in Oracle Forms Services (C/S, Charmode component) in Oracle Fusion Middleware. The vulnerability is accessed via HTTP and requires low-privilege authentication but does not require user interaction. An attacker with valid credentials and network access can exploit this vulnerability to achieve complete system compromise, including arbitrary code execution resulting in confidentiality, integrity, and availability impacts. Patched versions are expected to be available from Oracle; affected versions include 12.2.1.19.0 and 14.1.2.0.0.

Affected products

  • Oracle Forms 12.2.1.19.0 and 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References