A critical (CVSS 9.8) flaw in Oracle Application Testing Suite 13.3.0.1 lets an unauthenticated, network-based attacker fully compromise the product.
What Is It
CVE-2026-46924 is a critical vulnerability in Oracle Application Testing Suite. Per Oracle's advisory, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise the software. Successful exploitation can result in a complete takeover of Oracle Application Testing Suite. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting high impact to confidentiality, integrity, and availability.
Why It Matters
The combination of network attack vector, low attack complexity, and no required privileges or user interaction means an attacker can reach and exploit this vulnerability remotely without credentials. Oracle characterizes it as "easily exploitable," and successful attacks yield full takeover of the affected product; the maximum impact across all three security dimensions.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Application Testing Suite
- Affected version: 13.3.0.1 (the supported version identified as affected)
Patch Status
This vulnerability was addressed in Oracle's July 2026 Critical Patch Update. Administrators should consult the Oracle security alert referenced below and apply the corresponding fixes. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.
Sources
- NVD, CVE-2026-46924: https://nvd.nist.gov/vuln/detail/CVE-2026-46924
- Oracle Critical Patch Update Advisory (July 2026): https://www.oracle.com/security-alerts/cpujul2026.html