Vulnerability in Oracle Application Testing Suite Allows Unauthorized Data Access
CVE-2026-70864

7.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70864?

A vulnerability in Oracle Application Testing Suite allows an attacker with low privileges to exploit the system, gaining unauthorized access to sensitive data. The attack requires human interaction from an individual other than the attacker, making it easier to initiate but potentially disruptive for organizations. Compromised systems may lead to unauthorized updates, inserts, or deletions of accessible data, thereby affecting any products reliant on the Oracle Application Testing Suite. This vulnerability highlights the importance of securing web applications and the risks associated with insufficient access controls.

Affected Version(s)

Oracle Application Testing Suite 13.3.0.1

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.