Description
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the access control logic of Oracle Application Testing Suite 13.3.0.1 enables any network user to execute arbitrary code, which is classified as CWE-284. This weakness allows an attacker who can reach the service over TCP to fully compromise the instance, leading to loss of confidentiality, integrity, and availability for all data handled by the suite.

Affected Systems

Oracle Corporation’s Oracle Application Testing Suite version 13.3.0.1 is the only product listed as affected. No other vendors or product variants appear in the CNA data.

Risk and Exploitability

The CVSS v3.1 score of 9.8 indicates critical severity, and the EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability is not yet catalogued in CISA KEV. Based on the CVE description, the attack vector is inbound TCP to the service, requires no authentication, and can be executed from any remote host that can reach the vulnerable port.

Generated by OpenCVE AI on August 4, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security alerts and install any patch or update that addresses CVE-2026-46924 as soon as it becomes available.
  • Restrict inbound TCP traffic to the Application Testing Suite to only trusted hosts or IP ranges, using firewall rules or access control lists.
  • Place the Application Testing Suite in a segregated network segment or behind a bastion host to limit exposure to the wider network.
  • Continuously monitor Oracle’s security advisories and the CVE database for new exploitation activity or additional patches related to this vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Application Testing Suite 13.3.0.1 via TCP

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution in Oracle Application Testing Suite 13.3.0.1 via TCP

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Application Testing Suite via Unauthenticated TCP Access
Weaknesses CWE-78

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Application Testing Suite via Unauthenticated TCP Access
Weaknesses CWE-78

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Testing Suite
CPEs cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Testing Suite
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Testing Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:18:51.467Z

Reserved: 2026-05-18T15:55:10.311Z

Link: CVE-2026-46924

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:51.737Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:02.047

Modified: 2026-07-24T18:49:36.080

Link: CVE-2026-46924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses