CVE-2026-83096
Received Received - Intake

Cross-Site Scripting in Oracle Forms

Vulnerability report for CVE-2026-83096, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: Oracle

Description

Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as unauthorized access to critical data or complete access to all Oracle Forms accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Forms. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
oracle forms 12.2.1.19.0
oracle forms 14.1.2.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle Forms, part of Oracle Fusion Middleware. It affects versions 12.2.1.19.0 and 14.1.2.0.0. The issue allows a low-privileged attacker with network access via HTTP to potentially compromise Oracle Forms. Exploitation requires human interaction from someone other than the attacker.

Detection Guidance

Detection of CVE-2026-83096 requires monitoring Oracle Forms for unusual activity, such as unauthorized data access or modification attempts. Check Oracle Forms logs for HTTP requests with suspicious patterns or anomalies in user interactions. Ensure network traffic to Oracle Forms ports is inspected for unexpected behavior.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized creation, deletion, or modification of critical data within Oracle Forms. It may also grant unauthorized access to all Oracle Forms accessible data and cause a partial denial of service (DOS).

Compliance Impact

This vulnerability could lead to unauthorized access, modification, or deletion of critical data, which directly conflicts with GDPR's data integrity and confidentiality requirements and HIPAA's safeguards for protected health information. The potential for unauthorized data access or modification may result in non-compliance with these regulations.

Mitigation Strategies

Apply the latest security patches from Oracle for Oracle Forms versions 12.2.1.19.0 and 14.1.2.0.0. Restrict network access to Oracle Forms via HTTP to trusted sources only. Monitor for unusual data modification or deletion activities in Oracle Forms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83096. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart