ZeroHour

CVE-2026-83149

niche

Critical Authenticated Data-Access Flaw in Oracle Application Testing Suite 13.3.0.1

CVSS 3.1
9.1 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-83149 is an easily exploitable vulnerability in Oracle Application Testing Suite (OATS) version 13.3.0.1 that allows a low-privileged attacker holding the 'Test Manager for Web Apps' privilege to compromise the suite over HTTP via the network. The flaw carries a scope change (CVSS 3.1 score 9.1, vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L), meaning successful attacks on OATS may significantly impact additional products beyond it. A successful exploit gives the attacker unauthorized read access to critical data or complete access to all OATS-accessible data, unauthorized update, insert, or delete access to some of that data, and the ability to cause a partial denial of service. Only organizations running OATS 13.3.0.1 with network-reachable (HTTP) consoles and accounts with the Test Manager for Web Apps privilege are affected. No public proof of concept is known and the vulnerability is not on the CISA KEV list, so there is no indication of in-the-wild exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that remediated CVE-2026-83149 to all Oracle Application Testing Suite 13.3.0.1 installations. Restrict HTTP access to OATS consoles so only trusted QA networks and VPN clients can reach them, and review 'Test Manager for Web Apps' accounts for compromise, unexpected data access, or unauthorized modifications. Audit logs for anomalous activity and avoid exposing OATS endpoints directly to the internet.

Affected
Oracle Application Testing Suite
Estimated exposure
nichelikely hundreds to low thousands of on-premises OATS deployments worldwide — Oracle Application Testing Suite is a niche enterprise QA/testing product typically deployed on internal corporate networks for test teams, and no public install counts or internet-exposed device figures are available in the data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite. While the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.