Junglewise Threat Intelligence

CVE-2026-83107: Oracle Forms Remote Code Execution

CVE-2026-83107 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a core component of Oracle Fusion Middleware used to build and deploy business applications. This vulnerability allows a privileged network attacker to gain complete control over Forms Services, potentially compromising the confidentiality, integrity, and availability of the application and impacting downstream systems.

Technical details

A vulnerability in Oracle Forms Services (C/S Charmode component) allows remote code execution when exploited by a high-privileged attacker with network access via HTTP. The vulnerability affects Forms versions 12.2.1.19.0 and 14.1.2.0.0. Successful exploitation results in complete takeover of Oracle Forms with impacts extending beyond the Forms component itself (scope change). No patch information is currently available from the advisory text.

Affected products

  • Oracle Forms 12.2.1.19.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References