Description
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Application Testing Suite 13.3.0.1 contains a vulnerability that permits an unauthenticated attacker with network access to compromise the application. The flaw allows the attacker to take full control of the system, leading to loss of confidentiality, integrity, and availability. The vulnerability is exploitable over HTTP without requiring authentication or user interaction.

Affected Systems

The affected product is Oracle Corporation’s Oracle Application Testing Suite version 13.3.0.1. No other vendors or product versions are listed by the CNA for this entry.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates high severity. The EPSS score is < 1%, indicating a low probability of exploitation, but the lack of authentication requirements and an airborne attack vector over HTTP still make exploitation a realistic threat to any externally reachable instance. The vulnerability is not currently listed in the CISA KEV catalog, but its potential for full takeover warrants urgent attention. Attackers would send specially crafted HTTP requests to the exposed service, leveraging the flaw to execute arbitrary code.

Generated by OpenCVE AI on August 21, 2026 at 06:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for version 13.3.0.1 to close the vulnerability.
  • Restrict HTTP exposure by configuring network firewalls or VPNs to allow access only from trusted IP ranges, ensuring unauthenticated external traffic is blocked.
  • Deploy log monitoring and intrusion detection to flag anomalous HTTP activity and investigate potential exploitation attempts.

Generated by OpenCVE AI on August 21, 2026 at 06:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Compromise in Oracle Application Testing Suite 13.3.0.1
Weaknesses CWE-20
CWE-284

Fri, 21 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Oracle Application Testing Suite 13.3.0.1 Unauthenticated Remote Code Execution via HTTP
Weaknesses CWE-94

Wed, 19 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Oracle Application Testing Suite 13.3.0.1 Unauthenticated Remote Code Execution via HTTP
Weaknesses CWE-94

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Testing Suite
CPEs cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Testing Suite
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Testing Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:55:46.478Z

Reserved: 2026-08-04T22:06:34.602Z

Link: CVE-2026-70868

cve-icon Vulnrichment

Updated: 2026-08-24T14:55:42.120Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:43.110

Modified: 2026-08-27T18:37:09.117

Link: CVE-2026-70868

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T06:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-284

    Improper Access Control