SYS::ONLINE
Wasteland.
Briefs1404
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-35290 2026-07-21

CVE-2026-35290: Critical Unauthenticated Takeover in Oracle Application Testing Suite

"Oracle Application Testing Suite 13.3.0.1 contains a critical, network-exploitable flaw (CVSS 9.8) that lets an unauthenticated attacker fully compromise the product."

Oracle Application Testing Suite 13.3.0.1 contains a critical, network-exploitable flaw (CVSS 9.8) that lets an unauthenticated attacker fully compromise the product.

What Is It

CVE-2026-35290 is a vulnerability in Oracle Application Testing Suite, disclosed in Oracle's July 2026 Critical Patch Update. Per Oracle's advisory (via NVD), the flaw is "easily exploitable" and allows an unauthenticated attacker with network access over TCP to compromise the software. Successful exploitation can result in full takeover of Oracle Application Testing Suite. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, remote reachability over the network, and low attack complexity makes this an attractive target. Because successful attacks yield complete takeover, with high confidentiality, integrity, and availability impact, a compromised instance could be fully controlled by an attacker. The maximum-tier exploitability sub-score (3.9) reflects how little effort exploitation requires.

What's Vulnerable

The supplied data does not list additional affected versions or CPEs.

Patch Status

The vulnerability was published on 2026-07-21 and is addressed in Oracle's July 2026 Critical Patch Update. Organizations running Oracle Application Testing Suite 13.3.0.1 should consult and apply the fixes in the Oracle Critical Patch Update Advisory (July 2026). No CISA KEV entry was supplied, so there is no confirmation of active exploitation in the provided source material.

Sources