ZeroHour

CVE-2026-83148

niche

Low-Privilege Takeover Flaw in Oracle Application Testing Suite 13.3.0.1

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Oracle Application Testing Suite 13.3.0.1 contains an easily exploitable vulnerability that allows a low-privileged attacker holding the 'Test Manager for Web Apps' privilege, with network access via HTTP, to fully compromise the application. Successful attacks can result in complete takeover of the Oracle Application Testing Suite, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Only version 13.3.0.1 is listed as affected, and exploitation requires the attacker to already possess a valid low-privilege account rather than being fully unauthenticated. No public proof-of-concept or confirmed in-the-wild exploitation has been reported, and the flaw is not on the CISA Known Exploited Vulnerabilities catalog. The issue was disclosed through Oracle's Critical Patch Update process (CNA: [email protected]).

What to do: Upgrade Oracle Application Testing Suite from 13.3.0.1 to the release patched in the applicable Oracle Critical Patch Update. Restrict HTTP access to ATS consoles and web interfaces to trusted internal ranges or VPN, and audit accounts holding the 'Test Manager for Web Apps' privilege for legitimacy. Review logs for unexpected privilege changes, account creation, or configuration modifications on ATS hosts.

Affected
Oracle Application Testing Suite
Estimated exposure
nichelikely low thousands of installations worldwide, with an internet-exposed subset plausibly in the hundreds — Oracle Application Testing Suite is a specialized enterprise QA/testing product typically deployed on internal corporate networks, and public internet scans historically show only a small number of exposed ATS consoles.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.