A critical, easily exploitable flaw in Oracle Application Testing Suite 13.3.0.1 lets an unauthenticated attacker with network access fully compromise the product, and Oracle has shipped a fix in its July 2026 Critical Patch Update.
What Is It
CVE-2026-46876 is a critical vulnerability in Oracle Application Testing Suite. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via Oracle Net to compromise the software. A successful attack can result in complete takeover of Oracle Application Testing Suite.
The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network-based exploitation, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of no authentication, network reachability, low complexity, and full compromise makes this among the most severe vulnerability classes. A successful exploit yields takeover of the affected system, meaning an attacker could read, alter, or destroy data and disrupt availability. The maximum exploitability sub-score (3.9) underscores how little effort an attack requires.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Application Testing Suite
- Affected version: 13.3.0.1
The attack path is network access via Oracle Net.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators running Oracle Application Testing Suite 13.3.0.1 should apply the fixes referenced in that advisory without delay.
There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the provided source material. The NVD record status is "Received."