Description
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The defect is an access‑control flaw that can be triggered by sending a crafted HTTP request to Oracle Application Testing Suite 13.3.0.1 while logged in with the Load Testing for Web Apps role. The flaw allows a low‑privileged user to read critical data and, with additional human cooperation from a distinct user, to gain read access to all data in the suite and to perform unauthorized updates, inserts or deletes on data owned by other users, resulting in confidential data exposure and integrity violations.

Affected Systems

Only Oracle Application Testing Suite 13.3.0.1 is directly affected. The description indicates a scope change, meaning that successful exploitation could also threaten other Oracle products that interact with the suite.

Risk and Exploitability

The CVSS v3.1 base score of 7.6 classifies the issue as high severity, with confidentiality impact rated high and integrity low. The EPSS score of less than 1% suggests exploitation is unlikely but not impossible. The vulnerability is not yet listed in CISA's KEV catalog. Attackers need network reach to the HTTP endpoint and a low‑privilege Load Testing for Web Apps account; they also require a user other than themselves to provide assistance, which lowers the likelihood of a fully remote attack but remains a concern for environments where internal users grant such privileges.

Generated by OpenCVE AI on August 24, 2026 at 22:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest Oracle Application Testing Suite release that contains the fix for this flaw, or apply the vendor's patch if an upgrade is not immediately possible.
  • Restrict the Load Testing for Web Apps role to a minimum number of designated staff and enforce strict role‑based access controls so only trusted personnel can use the privilege.
  • Harden network exposure by placing the suite behind a VPN or firewall so that only approved hosts can reach the HTTP interface, and consider disabling public HTTP access where feasible.
  • Enable and regularly review audit logging to detect anomalous data read, write or delete actions that may indicate privilege abuse.

Generated by OpenCVE AI on August 24, 2026 at 22:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Oracle Application Testing Suite Enables Unauthorized Data Access

Mon, 24 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Oracle Application Testing Suite 13.3.0.1 Low-Privilege Data Access Exploitation
Weaknesses CWE-264
CWE-269

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Oracle Application Testing Suite 13.3.0.1 Low-Privilege Data Access Exploitation
Weaknesses CWE-264
CWE-269

Fri, 21 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Oracle Application Testing Suite 13.3.0.1 Access Control Vulnerability via HTTP
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Oracle Application Testing Suite 13.3.0.1 Access Control Vulnerability via HTTP
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle application Testing Suite
CPEs cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Testing Suite
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Application Testing Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:21:19.303Z

Reserved: 2026-08-04T22:06:34.602Z

Link: CVE-2026-70864

cve-icon Vulnrichment

Updated: 2026-08-24T14:07:49.654Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:42.620

Modified: 2026-08-27T18:37:27.970

Link: CVE-2026-70864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:45:03Z

Weaknesses