Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83105 2026-09-15

CVE-2026-83105: Critical Oracle Forms Takeover Flaw Crosses Product Boundaries

"Oracle has disclosed a CVSS 9.0 vulnerability in Oracle Forms that lets an unauthenticated remote attacker take over the product entirely, with a scope change that can drag neighboring products down with it."

Oracle has disclosed a CVSS 9.0 vulnerability in Oracle Forms that lets an unauthenticated remote attacker take over the product entirely, with a scope change that can drag neighboring products down with it.

What Is It

CVE-2026-83105 is a critical vulnerability in the Oracle Forms product of Oracle Fusion Middleware, specifically in the Forms Services, C/S, Charmode component. Per Oracle's advisory, an unauthenticated attacker with network access via HTTP can compromise Oracle Forms. Oracle rates the flaw "difficult to exploit," which is reflected in the CVSS attack complexity rating of HIGH. According to Oracle, successful attacks can result in takeover of Oracle Forms.

The CVSS 3.1 base score is 9.0 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H, exploitability subscore 2.2, impact subscore 6.0. The record was published by Oracle ([email protected]) on 2026-09-15 and currently carries NVD status "Received."

Why It Matters

Three things push this above routine patch-cycle noise. First, no authentication and no user interaction are required; network reachability over HTTP is the only prerequisite. Second, the rated impact is total: high confidentiality, integrity, and availability loss, described by Oracle as takeover. Third, and most consequential, the scope is CHANGED. Oracle explicitly notes that while the vulnerability resides in Oracle Forms, "attacks may significantly impact additional products." On Oracle's own description, a compromise may not stay contained to the Forms instance.

The HIGH attack complexity is the only meaningful brake here, and it is not a substitute for patching.

What's Vulnerable

Oracle lists two affected supported versions of Oracle Forms:

No CPE match data is present in the NVD record at this time.

Patch Status

The vulnerability is documented in Oracle's Critical Patch Update advisory at cspusep2026.html. Consult that advisory for the applicable patch for your version. The supplied source material contains no CISA KEV entry for CVE-2026-83105; there is no confirmation of active exploitation in the wild, and no KEV-mandated remediation deadline applies.

Sources