Oracle disclosed CVE-2026-83149, a critical (CVSS 9.1) vulnerability in Oracle Application Testing Suite 13.3.0.1 that lets a low-privileged network attacker compromise the product and reach beyond it into adjacent systems.
What Is It
The flaw sits in Oracle Application Testing Suite, in the Test Manager for Web Apps component. Per the advisory data, it is an easily exploitable vulnerability that allows a low-privileged attacker with network access over HTTP to compromise the suite. No user interaction is required.
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L, for a base score of 9.1 (Critical). Confidentiality impact is High; integrity and availability impacts are Low. The score is driven upward by the changed scope.
Why It Matters
The scope change is the headline. Oracle states that while the vulnerability resides in Oracle Application Testing Suite, attacks may significantly impact additional products. That is the vendor's own framing of the blast radius: a compromise here may not stay contained within the testing suite's security boundary, though the specific downstream products and the conditions required to reach them are not enumerated in the available data.
Successful exploitation can result in unauthorized access to critical data or complete access to all data accessible to Oracle Application Testing Suite, unauthorized update, insert, or delete access to some of that data, and the ability to cause a partial denial of service against the suite.
The low privilege bar matters too. This is not a pre-auth bug, but PR:L means only low-level privileges are required; no administrative access. Any account meeting that bar, including one obtained through credential reuse or a low-value phishing hit, is enough to begin. Treat every authenticated user of the testing suite as a potential starting point rather than assuming the authentication requirement is a meaningful barrier.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: Oracle Application Testing Suite
- Component: Test Manager for Web Apps
- Affected version: 13.3.0.1 (the supported version identified as affected)
No affected CPE records were present in the NVD data at time of writing.
Patch Status
The CVE was published 2026-09-15 and its NVD status is Received, meaning analysis is not yet complete. Oracle's own security advisory for this disclosure is the authoritative source for fix availability. Defenders should locate it through Oracle's Security Alerts and Critical Patch Update index rather than relying on a specific advisory filename or an assumed release cycle, and confirm the applicable patch there before planning remediation. Oracle issues Critical Patch Updates on a fixed quarterly schedule, with out-of-cycle Security Alerts published separately, so the index, not a constructed URL, is the reliable starting point.
There is no CISA KEV entry for CVE-2026-83149 in the supplied data. Active exploitation is therefore not confirmed, and no KEV-mandated remediation deadline or required action applies at this time.
Sources
- Oracle security advisory covering this disclosure; the referenced link is unverified and its filename does not match Oracle's published advisory naming or release cadence; treat it as a lead only and confirm the correct advisory through Oracle's Security Alerts and Critical Patch Update index: https://www.oracle.com/security-alerts/cspusep2026.html
- NVD, CVE-2026-83149: https://nvd.nist.gov/vuln/detail/CVE-2026-83149