Summary
CVE-2026-83101 is a vulnerability in the Forms Services (C/S, Charmode) component of Oracle Forms, part of Oracle Fusion Middleware. It allows an unauthenticated attacker with network access via HTTP to fully compromise Oracle Forms, resulting in a complete takeover of the affected system. Oracle rates the issue HIGH severity with a CVSS v3.1 base score of 8.1, though it is described by Oracle as difficult to exploit.
Technical details
- Root cause: A flaw in the Forms Services component of Oracle Forms, specifically within the C/S (client/server) and Charmode functionality.
- Trigger conditions: Oracle characterizes the vulnerability as difficult to exploit, but no authentication or user interaction is required to trigger it.
- Attack vector: Network-based, reachable over HTTP without prior authentication (Attack Vector: Network, Privileges Required: None, User Interaction: None).
- Impact: Successful exploitation results in takeover of Oracle Forms, with high impact to confidentiality, integrity, and availability of the affected deployment.
Affected software
- Oracle Forms (Oracle Fusion Middleware) version 12.2.1.19.0
- Oracle Forms (Oracle Fusion Middleware) version 14.1.2.0.0
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fixes provided in Oracle’s September 2026 Critical Patch Update (Critical Security Patch Update Advisory) for Oracle Fusion Middleware / Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0.
- If patching is not immediately possible: Restrict network exposure of Oracle Forms Services (HTTP listener and C/S, Charmode endpoints) to trusted networks only, and monitor for anomalous requests to the Forms Services listener until the patch can be applied.

