Sceawere

Vulnerability Detail

CVE-2026-70862UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Application Testing Suite Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Application Testing Suite
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Testing Suite accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Testing Suite accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-18T21:17:42.370Z",
  "pubdate": "2026-08-18T21:17:42.370Z",
  "executiveSummary": "An easily exploitable security vulnerability affects the Oracle Application Testing Suite, specifically targeting version 13.3.0.1. This vulnerability allows an unauthenticated remote attacker with network access via HTTP to compromise the affected system completely. Successful exploitation results in severe impacts on data integrity and confidentiality, granting unauthorized creation, deletion, and modification access to critical data, as well as complete unauthorized access to all accessible data within the Oracle Application Testing Suite. The vulnerability carries a CVSS 3.1 Base Score of 9.1 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. The high severity stems from the combination of network vector accessibility, low attack complexity, and the complete absence of authentication or user interaction requirements. This exposes organizational testing environments and sensitive assets to significant risk of data compromise, requiring immediate attention and remediation by system administrators.",
  "technicalDetails": "The vulnerability resides within the Oracle Application Testing Suite version 13.3.0.1 and exposes a critical flaw accessible via the HTTP protocol. The root cause enables remote adversaries to bypass security controls without requiring any prior authentication or user interaction. Exploitation has a low attack complexity, allowing unauthenticated threat actors over a network to interact directly with vulnerable components of the Oracle Application Testing Suite.\nThe attack flow begins when an external attacker leverages network access to dispatch specially crafted HTTP requests to the target Oracle Application Testing Suite instance. Because the application fails to properly validate inputs, authenticate incoming sessions, or enforce adequate access control mechanisms, the crafted payload is processed successfully by the vulnerable component.\nPost-exploitation impacts are severe regarding confidentiality and integrity. Once the request is processed, the attacker gains unauthorized read access to all data accessible by the Oracle Application Testing Suite, allowing the exfiltration of sensitive information. Furthermore, the attacker gains unauthorized write, update, and delete privileges, enabling them to arbitrarily create, modify, or destroy critical data stored or processed within the suite. The scope remains unchanged (S:U), but the direct impact on data assets is catastrophic.\nAttack prerequisites are minimal: the attacker requires only network connectivity to the vulnerable Oracle Application Testing Suite endpoint operating on version 13.3.0.1, alongside the ability to craft valid HTTP traffic capable of interacting with the exposed application interfaces. No privileges (PR:N) and no user interaction (UI:N) are necessary to execute the attack."
}
CVE-2026-70862: Oracle Application Testing Suite Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere