---
id: CVE-2026-83148
title: Vulnerability in Oracle Application Testing Suite
summary: >-
  Vulnerability in Oracle Application Testing Suite.   The supported version
  that is affected is 13.3.0.1. Easily exploitable vulnerability allows low
  privileged attacker having Test Manager for Web Apps privilege with network
  access via H…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: Oracle Corporation
product: Oracle Application Testing Suite
affected:
  - oracle_application_testing_suite 13.3.0.1
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:17:34.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-83148'
references:
  - url: 'https://www.oracle.com/security-alerts/cspusep2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T13:02:12.546278Z'
epss: 0.00417
epssPercentile: 0.35719
ingestedAt: '2026-09-15T20:44:02.469Z'
---

## Overview

Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
