CVE-2026-70865: High severity Oracle Oracle Application Testing Suite vulnerability
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Deployments of Oracle Application Testing Suite version 13.3.0.1 are affected when an attacker can reach the suite over HTTPS and has the Load Testing for Web Apps privilege.
What access does an attacker need to exploit it?
The attacker needs network access via HTTPS and an existing low-privileged account or access level with the Load Testing for Web Apps privilege. No user interaction is required, but exploitation is rated as difficult.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of Oracle Application Testing Suite, with high impacts to confidentiality, integrity, and availability.