Junglewise Threat Intelligence

CVE-2026-46876: Oracle Application Testing Suite remote compromise

CVE-2026-46876 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite, a platform used for automated software testing, contains a critical security flaw. An unauthorized person can gain full control over the system over the network without needing any login credentials. This could lead to the complete theft of testing data, disruption of software development cycles, and unauthorized access to sensitive corporate applications being tested.

Technical details

A critical vulnerability exists in Oracle Application Testing Suite version 13.3.0.1. The flaw is easily exploitable by an unauthenticated attacker with network access via the Oracle Net protocol. Successful exploitation allows for a complete takeover of the affected component, impacting confidentiality, integrity, and availability (CVSS 9.8). While specific CWE details are not provided in the advisory, the attack vector is network-based and requires no user interaction or prior privileges. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats