{"id":"CVE-2026-83148","title":"Vulnerability in Oracle Application Testing Suite","summary":"Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via H…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"vendor":"Oracle Corporation","product":"Oracle Application Testing Suite","affected":["oracle_application_testing_suite 13.3.0.1"],"published":"2026-09-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T14:17:34.520","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-83148","references":[{"url":"https://www.oracle.com/security-alerts/cspusep2026.html","label":"secalert_us@oracle.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-17T13:02:12.546278Z"},"epss":0.00417,"epssPercentile":0.35597,"ingestedAt":"2026-09-15T20:44:02.469Z","slug":"CVE-2026-83148","body":"## Overview\n\nVulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}