Junglewise Threat Intelligence

CVE-2026-83149: Oracle Application Testing Suite privilege escalation via HTTP

CVE-2026-83149 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite is a software tool used by enterprises to test web applications and validate their functionality. A vulnerability in version 13.3.0.1 allows an attacker with low-level access to gain unauthorized access to sensitive test data, modify or delete data, and cause service disruptions. The flaw can also impact other systems that depend on this testing platform, potentially affecting the security posture of applications under test.

Technical details

The vulnerability is an easily exploitable flaw in Oracle Application Testing Suite 13.3.0.1 that allows an attacker with "Test Manager for Web Apps" privilege and network access via HTTP to escalate their access. The vulnerability has a CVSS score of 9.1 with scope change (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L), indicating high confidentiality impact and partial integrity and availability impacts. An authenticated attacker can achieve unauthorized access to critical data, unauthorized modifications to test data, and partial denial of service. The exact root cause and patch availability details are not specified in the advisory.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-09-15: disclosed

References

Related threats