Vulnerability in Oracle Application Testing Suite Affects Low Privileged Users
CVE-2026-70865

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70865?

A security vulnerability exists in Oracle Application Testing Suite that allows a low privileged attacker with Load Testing for Web Apps privileges and network access via HTTPS to exploit the application. If successfully exploited, this vulnerability may lead to the complete takeover of the Oracle Application Testing Suite, impacting the confidentiality, integrity, and availability of the application. Organizations using version 13.3.0.1 are advised to implement the necessary updates as outlined in the vendor's advisory.

Affected Version(s)

Oracle Application Testing Suite 13.3.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.