Junglewise Threat Intelligence

CVE-2026-70864: Oracle Application Testing Suite remote code execution via HTTP

CVE-2026-70864 · Severity: high · CVSS 7.6 · Published 2026-08-18

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite is a tool used by enterprises to test web applications and load-test systems. This vulnerability allows an attacker with low-level privileges and Load Testing access to manipulate or steal sensitive test data by sending specially crafted HTTP requests. Successful exploitation requires tricking another user into clicking a link or performing an action, and can result in unauthorized access to test data or modification of critical test scenarios and results across the organization.

Technical details

The vulnerability is in Oracle Application Testing Suite 13.3.0.1 and is easily exploitable via network-accessible HTTP requests. An attacker with "Load Testing for Web Apps" privilege can exploit this flaw with low complexity and without additional authentication mechanisms (AC:L). The attack requires user interaction (UI:R) from a person other than the attacker and has a scope change (S:C), meaning it impacts resources beyond the vulnerable component. Successful exploitation grants high confidentiality impact (read access to critical data), low integrity impact (limited write access), and no availability impact. A patch or security update is likely available from Oracle's August 2026 security advisory.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-08-18: disclosed

References

Related threats