Description
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Application Compromise
Action: Assess Impact
AI Analysis

Impact

This vulnerability arises from an improper access control flaw that allows an attacker who has logon access to the infrastructure where Oracle Application Testing Suite runs to compromise the application. The flaw, identified as CWE‑269, enables takeover of the suite, resulting in loss of confidentiality, integrity and availability of all data processed by it. The likely attack vector is an unauthenticated attacker who can log into the host, but successful exploitation also requires human interaction from a party other than the attacker.

Affected Systems

Oracle application testing suite version 13.3.0.1 is the only product mentioned as affected.

Risk and Exploitability

The CVSS 3.1 base score of 7.0 indicates a moderate to high severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires attackers to first obtain local logon access to the infrastructure and then rely on a human facilitator; therefore the risk is lower in environments with strict internal controls. Nonetheless, once achieved, the attacker can gain full control of the suite and compromise all data it handles.

Generated by OpenCVE AI on September 20, 2026 at 11:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑issued security patch or update for version 13.3.0.1 as soon as it becomes available.
  • Restrict infrastructure access to the Oracle Application Testing Suite to authorized personnel only, enforcing least privilege and separation of duties.
  • Implement monitoring and alerting for unusual authentication events or anomalous activity within the Oracle Application Testing Suite environment.

Generated by OpenCVE AI on September 20, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access with Human Interaction Enables Oracle Application Testing Suite Compromise

Sun, 20 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Infrastructure Attack Compromises Oracle Application Testing Suite
Weaknesses CWE-20
CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Infrastructure Attack Compromises Oracle Application Testing Suite
Weaknesses CWE-20
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle application Testing Suite
CPEs cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Testing Suite
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Application Testing Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:10:43.476Z

Reserved: 2026-08-31T15:40:57.343Z

Link: CVE-2026-83150

cve-icon Vulnrichment

Updated: 2026-09-17T13:02:10.663Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:25.750

Modified: 2026-09-17T14:17:34.647

Link: CVE-2026-83150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T11:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management