Executive brief
Oracle Application Testing Suite is a test automation platform used by enterprises to validate applications. A privilege escalation vulnerability allows attackers with low-level access ("Load Testing for Web Apps" privilege) to gain full control of the Application Testing Suite, potentially compromising all test assets, data, and infrastructure it manages.
Technical details
A privilege escalation vulnerability exists in Oracle Application Testing Suite 13.3.0.1. The vulnerability requires local access to the infrastructure where the suite executes, combined with a low-privileged account holding the "Load Testing for Web Apps" privilege. Exploitation does not require user interaction. A successful attack grants the attacker full control (confidentiality, integrity, and availability impact) over the Oracle Application Testing Suite, enabling complete system compromise.
Affected products
- Oracle Application Testing Suite 13.3.0.1
Timeline
- 2026-08-18: disclosed