Junglewise Threat Intelligence

CVE-2026-83148: Oracle Application Testing Suite privilege escalation

CVE-2026-83148 · Severity: high · CVSS 8.8 · Published 2026-09-15

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite is a web-based testing management tool used by development teams. This vulnerability allows a low-privileged user with Test Manager rights to take complete control of the application, potentially compromising confidentiality, integrity, and availability of testing data and operations.

Technical details

An easily exploitable vulnerability in Oracle Application Testing Suite 13.3.0.1 allows a low-privileged attacker with Test Manager for Web Apps role to escalate privileges and take over the system. The vulnerability is reachable over the network via HTTP and requires only low privileges and no user interaction. Successful exploitation results in full compromise of confidentiality, integrity, and availability (CIA triad). The exact root cause and vulnerable component are not disclosed in available advisories.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-09-15: disclosed

References

Related threats