Junglewise Threat Intelligence

CVE-2026-70867: Oracle Application Testing Suite adjacent network access privilege escalation

CVE-2026-70867 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite is a quality assurance platform used by enterprises to test and validate business applications. This vulnerability allows an attacker with physical access to the network segment where the testing suite runs to bypass authentication and gain unauthorized access to sensitive testing data and potentially modify application test results without authorization. This poses a risk to data confidentiality and the integrity of application testing processes.

Technical details

This is an adjacently-exploitable vulnerability in Oracle Application Testing Suite version 13.3.0.1 that requires no authentication and no user interaction. The vulnerability allows an attacker with access to the same network segment (physical communication segment) as the affected system to compromise the application and gain unauthorized access to critical testing data, as well as perform unauthorized modifications (insert, update, delete) to data stored within the suite. The exact root cause is not disclosed in available advisory text, but the attack vector is classified as adjacent network access with low complexity and high confidentiality impact combined with limited integrity impact. Patches are expected from Oracle's security update process.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-08-18: disclosed

References

Related threats