Oracle disclosed a CVSS 9.1 vulnerability in Oracle Forms (Oracle Fusion Middleware) that lets a network-based, high-privileged attacker take over the product and, per Oracle, potentially reach beyond it into adjacent components.
What Is It
CVE-2026-83103 is a vulnerability in the Oracle Forms product of Oracle Fusion Middleware, specifically in the Forms Services, C/S, Charmode component. Oracle rates it as easily exploitable: an attacker with network access over HTTP and high privileges can compromise Oracle Forms with no user interaction required. Successful exploitation results in complete takeover of Oracle Forms.
The CVSS 3.1 base score is 9.1 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The record was published by Oracle's security alert channel on 2026-09-15 and is currently in NVD Received status, meaning NVD enrichment is not yet complete.
Why It Matters
Two things push this above a routine high-privilege bug. First, the scope is marked Changed; Oracle states that while the vulnerability resides in Oracle Forms, attacks may significantly impact additional products. On Oracle's own framing, a compromise is not guaranteed to stay contained in the Forms tier.
Second, the impact is total across all three axes: high confidentiality, high integrity, and high availability. Combined with low attack complexity and network reachability over HTTP, an attacker who has already obtained privileged access, through credential theft, a compromised admin account, or an insider position, can convert that foothold into full product takeover, with possible knock-on impact to adjacent products.
The mitigating factor is the PR:H requirement. This is not an unauthenticated internet-facing exploit; it requires high privileges to begin with.
KEV status: No CISA Known Exploited Vulnerabilities entry was supplied for this CVE. There is no confirmation of active exploitation in the wild at this time.
What's Vulnerable
The supplied data lists two affected Oracle Forms release lines:
- Oracle Forms 14.1.2.0.0
- A 12.2.1.x release, given in the source data as "12.2.1.19.0"
Treat the second entry with caution. Oracle Fusion Middleware 12.2.1 ships as numbered patch set releases in a much lower range, so a "12.2.1.19.0" string does not correspond to a recognizable Fusion Middleware release designation and is likely a transcription or data-entry artifact rather than a real shipped version. Administrators on any supported 12.2.1 Forms release should verify their exact version against Oracle's advisory rather than filtering on that string. The 14.1.2.0.0 entry is consistent with Oracle's current release numbering.
Vendor: Oracle Corporation. No CPE data is present in the NVD record yet.
Patch Status
Oracle published this through its security alerts channel. Administrators running affected Forms versions should locate the corresponding advisory on Oracle's security alerts index, confirm the precise affected version list there, and apply the patch it specifies. No specific fixed version number or CISA-mandated remediation deadline is present in the supplied data.
Sources
- NVD, CVE-2026-83103: https://nvd.nist.gov/vuln/detail/CVE-2026-83103
- Oracle Security Alerts: https://www.oracle.com/security-alerts/