Junglewise Threat Intelligence

CVE-2026-46924: Oracle Application Testing Suite remote compromise

CVE-2026-46924 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite, a platform used for automated software testing and quality assurance, contains a critical vulnerability. An unauthorized attacker can remotely access the system over the network without needing a username or password. If exploited, this could allow a complete takeover of the testing environment, potentially exposing sensitive application data or disrupting software development lifecycles.

Technical details

A critical vulnerability exists in Oracle Application Testing Suite version 13.3.0.1. The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via TCP to compromise the application. Successful exploitation results in a complete takeover of the Oracle Application Testing Suite, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation guidance.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats