---
id: CVE-2026-83149
title: Vulnerability in Oracle Application Testing Suite
summary: >-
  Vulnerability in Oracle Application Testing Suite.   The supported version
  that is affected is 13.3.0.1. Easily exploitable vulnerability allows low
  privileged attacker having Test Manager for Web Apps privilege with network
  access via H…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'
cwe:
  - CWE-284
vendor: Oracle Corporation
product: Oracle Application Testing Suite
affected:
  - oracle_application_testing_suite 13.3.0.1
published: '2026-09-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:19:05.527'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-83149'
references:
  - url: 'https://www.oracle.com/security-alerts/cspusep2026.html'
    label: secalert_us@oracle.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T16:25:48.668509Z'
epss: 0.00236
epssPercentile: 0.14825
ingestedAt: '2026-09-15T20:44:02.469Z'
---

## Overview

Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite.  While the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as  unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L).

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
