Executive brief
A critical vulnerability has been identified in the Oracle Application Testing Suite, a platform used by organizations to automate the testing of web and packaged applications. This flaw allows an unauthorized person to gain full control over the testing environment remotely without needing any login credentials. An exploit could lead to the theft of sensitive testing data, disruption of software quality assurance processes, and unauthorized access to connected systems.
Technical details
This vulnerability in Oracle Application Testing Suite (version 13.3.0.1) is characterized by its ease of exploitation and high impact. It allows an unauthenticated attacker with network access via TCP to compromise the application entirely. The root cause is not specified in the advisory, but the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates a remote, low-complexity attack requiring no user interaction or privileges. Successful exploitation results in a complete takeover of the suite, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Application Testing Suite 13.3.0.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 Critical Patch Update.
- 2026-07-21: advisory: NVD record published.