Junglewise Threat Intelligence

CVE-2026-83150: Oracle Application Testing Suite privilege escalation

CVE-2026-83150 · Severity: high · CVSS 7 · Published 2026-09-15

Technologies: Oracle Application Testing Suite. Vendors: Oracle.

Executive brief

Oracle Application Testing Suite is enterprise software used for automated testing and quality assurance of applications. A vulnerability in version 13.3.0.1 allows an authenticated local attacker with infrastructure access to gain full system compromise (takeover) of the testing platform if a user interacts with a malicious input. The impact includes loss of confidentiality, integrity, and availability of the testing environment.

Technical details

A privilege escalation vulnerability in Oracle Application Testing Suite 13.3.0.1 requires local infrastructure access and user interaction (social engineering or phishing vector), but no pre-existing authenticated account to the application itself. The vulnerability allows an unauthenticated attacker with physical or infrastructure-level access to execute arbitrary code or operations with elevated privileges. The attack is difficult to exploit due to the combination of requiring local access, lack of authentication, and mandatory user interaction. Patch status information is not available in the advisory.

Affected products

  • Oracle Application Testing Suite 13.3.0.1

Timeline

  • 2026-09-15: disclosed

References

Related threats