Junglewise Threat Intelligence

CVE-2026-70863: Oracle Application Testing Suite privilege escalation via HTTPS

CVE-2026-70863 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite is used by development and QA teams to automate load testing of web applications. A vulnerability allows users with Load Testing privileges to gain complete control of the entire application through an HTTPS connection, potentially compromising sensitive test data, intellectual property, and operational systems.

Technical details

This easily exploitable vulnerability in Oracle Application Testing Suite affects version 13.3.0.1 and allows privilege escalation when accessed via HTTPS. An attacker with low-privilege "Load Testing for Web Apps" permissions can leverage the flaw to gain complete system compromise, affecting confidentiality, integrity, and availability. The attack requires network access and valid credentials but no user interaction. No patch availability information was publicly disclosed at the time of advisory publication.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-08-18: disclosed

References

Related threats