Description
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker possessing the Load Testing for Web Apps privilege can exploit a flaw in Oracle Application Testing Suite 13.3.0.1, enabling full compromise of the application. Successful exploitation results in loss of confidentiality, integrity and availability of the suite and effectively allows the attacker to take over the system. The vulnerability is scored 7.8 on the CVSS v3.1 scale, indicating a high level of risk for affected installations.

Affected Systems

Oracle Corporation’s Oracle Application Testing Suite, version 13.3.0.1. No other affected versions are listed.

Risk and Exploitability

The CVSS vector indicates a local attack with low attack complexity, low privileges, no user interaction, and a single scope. Because the EPSS score is reported as <1% and the vulnerability is not listed in CISA KEV, the likelihood of widespread exploitation cannot be determined precisely. The high confidentiality, integrity, and availability impact, combined with the low attack effort, suggests a serious threat. Detection would be limited to the infrastructure where the Suite operates and would require that the attacker already has Load Testing for Web Apps privileges; this conclusion is inferred from the CVSS vector and description.

Generated by OpenCVE AI on August 24, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch or upgrade to a version that resolves the issue.
  • If immediate patching is not possible, restrict Load Testing for Web Apps privilege to a trusted, limited set of users and ensure they are monitored.
  • Enable comprehensive logging and audit trails for Application Testing Suite activities to detect suspicious attempts.

Generated by OpenCVE AI on August 24, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Oracle Application Testing Suite 13.3.0.1 Local Privilege Escalation via Load Testing Privilege

Mon, 24 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Application Testing Suite 13.3.0.1
Weaknesses CWE-640

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Application Testing Suite 13.3.0.1
Weaknesses CWE-640

Fri, 21 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Exploit Allows Takeover of Oracle Application Testing Suite
Weaknesses CWE-284

Wed, 19 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Exploit Allows Takeover of Oracle Application Testing Suite
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Testing Suite
CPEs cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Testing Suite
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Testing Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:20:40.155Z

Reserved: 2026-08-04T22:06:34.602Z

Link: CVE-2026-70866

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:32.773Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:42.863

Modified: 2026-08-27T18:36:48.447

Link: CVE-2026-70866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:00:06Z

Weaknesses