Junglewise Threat Intelligence

CVE-2026-70866: Oracle Application Testing Suite privilege escalation

CVE-2026-70866 · Severity: high · CVSS 7.8 · Published 2026-08-18

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite is a test automation platform used by enterprises to validate applications. A privilege escalation vulnerability allows attackers with low-level access ("Load Testing for Web Apps" privilege) to gain full control of the Application Testing Suite, potentially compromising all test assets, data, and infrastructure it manages.

Technical details

A privilege escalation vulnerability exists in Oracle Application Testing Suite 13.3.0.1. The vulnerability requires local access to the infrastructure where the suite executes, combined with a low-privileged account holding the "Load Testing for Web Apps" privilege. Exploitation does not require user interaction. A successful attack grants the attacker full control (confidentiality, integrity, and availability impact) over the Oracle Application Testing Suite, enabling complete system compromise.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-08-18: disclosed

References

Related threats