Junglewise Threat Intelligence

CVE-2026-70862: Oracle Application Testing Suite unauthenticated remote data access

CVE-2026-70862 · Severity: critical · CVSS 9.1 · Published 2026-08-18

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite is a test automation platform used by enterprises to validate software quality. This vulnerability allows an unauthenticated attacker on the network to read, modify, or delete critical data in the application without requiring any credentials, compromising both confidentiality and integrity of test data and configurations.

Technical details

This is an unauthenticated remote code or data access vulnerability in Oracle Application Testing Suite 13.3.0.1, exploitable via HTTP with no user interaction required. The vulnerability allows an attacker with network access to bypass authentication mechanisms and gain unauthorized access to critical data, including creation, deletion, and modification capabilities. The attack has a network vector, requires no authentication or special privileges, and impacts both confidentiality (complete data disclosure) and integrity (unauthorized modification). A patch is expected to be available through Oracle's security update channels.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-08-18: disclosed

References

Related threats