Sceawere
Vulnerability Detail
CVE-2026-70863UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Application Testing Suite Takeover Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Application Testing Suite
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Load Testing for Web Apps privilege with network access via HTTPS to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:17:42.490Z",
"pubdate": "2026-08-18T21:17:42.490Z",
"executiveSummary": "A vulnerability has been identified in Oracle Application Testing Suite version 13.3.0.1 that allows an authenticated, low-privileged attacker to achieve a complete system takeover. The vulnerability resides within the Load Testing for Web Apps component and is remotely exploitable over the network via HTTPS.\nThe flaw presents significant risk to organizational security, as successful exploitation results in complete compromise of confidentiality, integrity, and availability with a CVSS 3.1 Base Score of 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).\nTo exploit this vulnerability, an attacker requires network connectivity to the target environment, valid credentials possessing Load Testing for Web Apps privileges, and no user interaction. Given the low attack complexity and the severe impact culminating in total application takeover, remediation is critical for affected deployments.",
"technicalDetails": "The vulnerability affects Oracle Application Testing Suite version 13.3.0.1, specifically targeting the Load Testing for Web Apps functionality. The root cause stems from insufficient access controls, insecure deserialization, or improper input validation within the administrative or execution workflows associated with the load testing mechanism, enabling a low-privileged user to execute unauthorized administrative actions or arbitrary code execution.\nThe attack vector is network-based (AV:N), utilizing the HTTPS protocol to interact with the vulnerable application endpoints. Exploitation requires low privileges (PR:L), meaning the attacker must authenticate with a standard user account that has been granted the Load Testing for Web Apps privilege. No user interaction (UI:N) is required on the victim's part, and the attack complexity is low (AC:L), allowing for reliable execution by an unauthorized entity.\nDuring the attack flow, the malicious actor leverages their assigned privileges to send specially crafted requests via HTTPS to the vulnerable Oracle Application Testing Suite components. Due to the lack of proper authorization checks or input sanitization within the vulnerable component, the application processes the input in a manner that bypasses security boundaries. This manipulation permits the escalation of privileges or direct execution of administrative functions.\nPost-exploitation impact includes a complete system takeover (S:U, C:H, I:H, A:H). Once the attacker successfully exploits the flaw, they gain full control over the Oracle Application Testing Suite instance, allowing them to access sensitive data, manipulate application logic, alter system configurations, or disrupt availability, thereby compromising the underlying host environment depending on the service account permissions."
}