Description
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Application Testing Suite version 13.3.0.1 allows a low‑privileged user who holds the Load Testing for Web Apps role to compromise the system via HTTPS. Successful exploitation grants the attacker control over the entire application testing environment, resulting in loss of confidentiality, integrity, and availability. The CVSS 3.1 base score of 7.5 reflects a high severity risk with all three impact dimensions affected.

Affected Systems

Affected systems include Oracle Corporation’s Oracle Application Testing Suite 13.3.0.1. No other versions are listed as impacted in the current advisories.

Risk and Exploitability

The CVSS base score indicates high severity, and the EPSS score of < 1 % suggests a very low likelihood of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a low‑privileged Load Testing user and occurs over HTTPS, enabling remote control of the application testing suite.

Generated by OpenCVE AI on August 25, 2026 at 00:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses CVE-2026-70865
  • Remove or restrict the Load Testing for Web Apps privilege from all users until the patch is deployed
  • Configure firewall or network segmentation rules to block or monitor anomalous HTTPS traffic directed at the Application Testing Suite

Generated by OpenCVE AI on August 25, 2026 at 00:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Oracle Application Testing Suite Remote Takeover via Low-Privileged Load Testing

Mon, 24 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Load Testing Role Enables Full Suite Takeover in Oracle Application Testing Suite 13.3.0.1
Weaknesses CWE-269

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Load Testing Role Enables Full Suite Takeover in Oracle Application Testing Suite 13.3.0.1
Weaknesses CWE-269

Fri, 21 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Load Testing User Can Compromise Oracle Application Testing Suite
Weaknesses CWE-284

Wed, 19 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Load Testing User Can Compromise Oracle Application Testing Suite
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Testing Suite
CPEs cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Testing Suite
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Testing Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:20:48.913Z

Reserved: 2026-08-04T22:06:34.602Z

Link: CVE-2026-70865

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:34.000Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:42.743

Modified: 2026-08-27T18:36:57.497

Link: CVE-2026-70865

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T00:15:04Z

Weaknesses