SYS::ONLINE
Wasteland.
Briefs1413
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-46924 2026-07-21

CVE-2026-46924: Critical Unauthenticated Takeover in Oracle Application Testing Suite

"A critical (CVSS 9.8) flaw in Oracle Application Testing Suite 13.3.0.1 lets an unauthenticated, network-based attacker fully compromise the product."

A critical (CVSS 9.8) flaw in Oracle Application Testing Suite 13.3.0.1 lets an unauthenticated, network-based attacker fully compromise the product.

What Is It

CVE-2026-46924 is a critical vulnerability in Oracle Application Testing Suite. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise the software. Successful exploitation can result in a complete takeover of Oracle Application Testing Suite. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of network attack vector, low attack complexity, and no required privileges or user interaction means an attacker can reach and exploit this vulnerability remotely without credentials. Oracle characterizes it as "easily exploitable," and successful attacks yield full takeover of the affected product; the maximum impact across all three security dimensions.

What's Vulnerable

Patch Status

This vulnerability was addressed in Oracle's July 2026 Critical Patch Update. Administrators should consult the Oracle security alert referenced below and apply the corresponding fixes. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.

Sources