SYS::ONLINE
Wasteland.
Briefs1404
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-46876 2026-07-21

CVE-2026-46876: Critical Unauthenticated Takeover in Oracle Application Testing Suite

"A critical, easily exploitable flaw in Oracle Application Testing Suite 13.3.0.1 lets an unauthenticated attacker with network access fully compromise the product, and Oracle has shipped a fix in its July 2026 Critical…"

A critical, easily exploitable flaw in Oracle Application Testing Suite 13.3.0.1 lets an unauthenticated attacker with network access fully compromise the product, and Oracle has shipped a fix in its July 2026 Critical Patch Update.

What Is It

CVE-2026-46876 is a critical vulnerability in Oracle Application Testing Suite. According to Oracle's advisory, the flaw is "easily exploitable" and allows an unauthenticated attacker with network access via Oracle Net to compromise the software. A successful attack can result in complete takeover of Oracle Application Testing Suite.

The issue carries a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting network-based exploitation, low attack complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of no authentication, network reachability, low complexity, and full compromise makes this among the most severe vulnerability classes. A successful exploit yields takeover of the affected system, meaning an attacker could read, alter, or destroy data and disrupt availability. The maximum exploitability sub-score (3.9) underscores how little effort an attack requires.

What's Vulnerable

The attack path is network access via Oracle Net.

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (cpujul2026). Administrators running Oracle Application Testing Suite 13.3.0.1 should apply the fixes referenced in that advisory without delay.

There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the provided source material. The NVD record status is "Received."

Sources