ZeroHour

CVE-2026-83150

niche

Unauthenticated Takeover Flaw in Oracle Application Testing Suite 13.3.0.1

CVSS 3.1
7.0 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83150 is a difficult-to-exploit, unauthenticated vulnerability in Oracle Application Testing Suite (OATS) version 13.3.0.1 that can allow an attacker with logon access to the infrastructure where OATS executes to take over the application. Exploitation is local-attack-vector only (AV:L), requires no privileges, but carries high attack complexity and depends on human interaction from a person other than the attacker, meaning a victim must be socially engineered into triggering the malicious action. A successful attack results in full compromise of OATS with high impacts to confidentiality, integrity, and availability (CVSS 3.1 base score 7.0). Organizations running the affected 13.3.0.1 release in their test/QA environments are at risk, though the practical barrier to exploitation is high. No public proof-of-concept is known, the flaw is not on the CISA KEV list, and there are no reports of in-the-wild exploitation.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-83150 and move off OATS 13.3.0.1 to the patched release. Restrict OS-level accounts and remote access on hosts running OATS to reduce the pool of attackers with the required infrastructure logon. Train admins and QA staff to be suspicious of unsolicited links or actions, since the attack chain depends on tricking a legitimate user into interacting with attacker-crafted content.

Affected
Oracle Application Testing Suite13.3.0.1
Estimated exposure
nicheunknown; plausibly hundreds to low thousands of enterprise QA deployments — Oracle Application Testing Suite is a licensed, on-premises enterprise testing tool with no public install counts, typically deployed once per organization's test environment, so no reliable census exists.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.