Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Tue, 25 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle Application Testing Suite Remote Takeover via Low-Privileged Load Testing |
Mon, 24 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege Load Testing Role Enables Full Suite Takeover in Oracle Application Testing Suite 13.3.0.1 | |
| Weaknesses | CWE-269 |
Mon, 24 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Fri, 21 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege Load Testing Role Enables Full Suite Takeover in Oracle Application Testing Suite 13.3.0.1 | |
| Weaknesses | CWE-269 |
Fri, 21 Aug 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege Load Testing User Can Compromise Oracle Application Testing Suite | |
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low-Privilege Load Testing User Can Compromise Oracle Application Testing Suite | |
| Weaknesses | CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle application Testing Suite |
|
| CPEs | cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle application Testing Suite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:02:14.065Z
Updated: 2026-08-24T15:20:48.913Z
Reserved: 2026-08-04T22:06:34.602Z
Link: CVE-2026-70865
Updated: 2026-08-24T15:12:34.000Z
Status : Analyzed
Published: 2026-08-18T21:17:42.743
Modified: 2026-08-27T18:36:57.497
Link: CVE-2026-70865
No data.