Junglewise Threat Intelligence

CVE-2026-83108: Oracle Forms unauthenticated remote code execution

CVE-2026-83108 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Forms is a low-code development platform used to build enterprise business applications within Oracle Fusion Middleware. An unauthenticated attacker can remotely exploit this vulnerability over the network without user interaction, leading to complete compromise of the Forms system including unauthorized access to data, modification of application logic, and service disruption.

Technical details

The vulnerability exists in Oracle Forms Services (C/S Charmode component) and is easily exploitable via HTTP by an unauthenticated network attacker. The attack requires no authentication, no special privileges, and no user interaction. Successful exploitation results in complete system takeover of the Oracle Forms instance, allowing an attacker to achieve arbitrary code execution with full confidentiality, integrity, and availability impact. The vulnerability affects Forms versions 12.2.1.19.0 and 14.1.2.0.0. Patch availability and specific remediation details are referenced in Oracle's security advisories.

Affected products

  • Oracle Forms 12.2.1.19.0, 14.1.2.0.0

Timeline

  • 2026-09-15: disclosed

References