Cyber & AI intelligence
Wasteland.
Briefs indexed2663
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-83149 2026-09-15

Oracle Application Testing Suite Hit With Critical 9.1 Scope-Change Flaw

"Oracle disclosed CVE-2026-83149, a critical (CVSS 9.1) vulnerability in Oracle Application Testing Suite 13.3.0.1 that lets a low-privileged network attacker compromise the product and reach beyond it into adjacent…"

Oracle disclosed CVE-2026-83149, a critical (CVSS 9.1) vulnerability in Oracle Application Testing Suite 13.3.0.1 that lets a low-privileged network attacker compromise the product and reach beyond it into adjacent systems.

What Is It

The flaw sits in Oracle Application Testing Suite, in the Test Manager for Web Apps component. Per the advisory data, it is an easily exploitable vulnerability that allows a low-privileged attacker with network access over HTTP to compromise the suite. No user interaction is required.

The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L, for a base score of 9.1 (Critical). Confidentiality impact is High; integrity and availability impacts are Low. The score is driven upward by the changed scope.

Why It Matters

The scope change is the headline. Oracle states that while the vulnerability resides in Oracle Application Testing Suite, attacks may significantly impact additional products. That is the vendor's own framing of the blast radius: a compromise here may not stay contained within the testing suite's security boundary, though the specific downstream products and the conditions required to reach them are not enumerated in the available data.

Successful exploitation can result in unauthorized access to critical data or complete access to all data accessible to Oracle Application Testing Suite, unauthorized update, insert, or delete access to some of that data, and the ability to cause a partial denial of service against the suite.

The low privilege bar matters too. This is not a pre-auth bug, but PR:L means only low-level privileges are required; no administrative access. Any account meeting that bar, including one obtained through credential reuse or a low-value phishing hit, is enough to begin. Treat every authenticated user of the testing suite as a potential starting point rather than assuming the authentication requirement is a meaningful barrier.

What's Vulnerable

No affected CPE records were present in the NVD data at time of writing.

Patch Status

The CVE was published 2026-09-15 and its NVD status is Received, meaning analysis is not yet complete. Oracle's own security advisory for this disclosure is the authoritative source for fix availability. Defenders should locate it through Oracle's Security Alerts and Critical Patch Update index rather than relying on a specific advisory filename or an assumed release cycle, and confirm the applicable patch there before planning remediation. Oracle issues Critical Patch Updates on a fixed quarterly schedule, with out-of-cycle Security Alerts published separately, so the index, not a constructed URL, is the reliable starting point.

There is no CISA KEV entry for CVE-2026-83149 in the supplied data. Active exploitation is therefore not confirmed, and no KEV-mandated remediation deadline or required action applies at this time.

Sources