CVE-2026-83148
nicheLow-Privilege Takeover Flaw in Oracle Application Testing Suite 13.3.0.1
Oracle Application Testing Suite 13.3.0.1 contains an easily exploitable vulnerability that allows a low-privileged attacker holding the 'Test Manager for Web Apps' privilege, with network access via HTTP, to fully compromise the application. Successful attacks can result in complete takeover of the Oracle Application Testing Suite, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Only version 13.3.0.1 is listed as affected, and exploitation requires the attacker to already possess a valid low-privilege account rather than being fully unauthenticated. No public proof-of-concept or confirmed in-the-wild exploitation has been reported, and the flaw is not on the CISA Known Exploited Vulnerabilities catalog. The issue was disclosed through Oracle's Critical Patch Update process (CNA: [email protected]).
What to do: Upgrade Oracle Application Testing Suite from 13.3.0.1 to the release patched in the applicable Oracle Critical Patch Update. Restrict HTTP access to ATS consoles and web interfaces to trusted internal ranges or VPN, and audit accounts holding the 'Test Manager for Web Apps' privilege for legitimacy. Review logs for unexpected privilege changes, account creation, or configuration modifications on ATS hosts.
| Oracle Application Testing Suite | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.