CVE-2026-83149
nicheCritical Authenticated Data-Access Flaw in Oracle Application Testing Suite 13.3.0.1
CVE-2026-83149 is an easily exploitable vulnerability in Oracle Application Testing Suite (OATS) version 13.3.0.1 that allows a low-privileged attacker holding the 'Test Manager for Web Apps' privilege to compromise the suite over HTTP via the network. The flaw carries a scope change (CVSS 3.1 score 9.1, vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L), meaning successful attacks on OATS may significantly impact additional products beyond it. A successful exploit gives the attacker unauthorized read access to critical data or complete access to all OATS-accessible data, unauthorized update, insert, or delete access to some of that data, and the ability to cause a partial denial of service. Only organizations running OATS 13.3.0.1 with network-reachable (HTTP) consoles and accounts with the Test Manager for Web Apps privilege are affected. No public proof of concept is known and the vulnerability is not on the CISA KEV list, so there is no indication of in-the-wild exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83149 to all Oracle Application Testing Suite 13.3.0.1 installations. Restrict HTTP access to OATS consoles so only trusted QA networks and VPN clients can reach them, and review 'Test Manager for Web Apps' accounts for compromise, unexpected data access, or unauthorized modifications. Audit logs for anomalous activity and avoid exposing OATS endpoints directly to the internet.
| Oracle Application Testing Suite | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. While the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.