CVE-2026-35290 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-35290 requires immediate attention.

· 7 min read

Executive Summary

CVE-2026-35290 is a critical unauthenticated remote compromise in Oracle Application Testing Suite 13.3.0.1. Oracle rates this issue CVSS 9.8 with full confidentiality, integrity, and availability impact. An attacker with network access over TCP can potentially take over the affected Application Testing Suite instance without credentials or user interaction.

This is not currently known to be exploited in the wild and is not in CISA KEV, but the attack conditions are simple enough that small teams should treat it as an urgent patch-and-isolate event. If you run Oracle Application Testing Suite in any environment exposed to internal networks, VPNs, CI/CD runners, or the public internet, assume it is at risk until proven otherwise.

Immediate Action

  • Patch immediately to the first Oracle-fixed release for Application Testing Suite. Vendor advisory
  • Isolate the service now if patching cannot happen within hours: restrict TCP access to only trusted admin hosts, jump boxes, or a temporary maintenance subnet.
  • Remove public exposure from load balancers, reverse proxies, port forwards, and security group rules. Do not leave the service reachable from broad internal networks.
  • Back up and snapshot the application host, configs, and data before changes so you can roll back if the patch disrupts test workflows.
  • Rotate secrets used by the suite after patching, especially service accounts, API keys, database credentials, and any credentials stored in the app.
  • Review logs for suspicious access to the suite’s TCP ports and admin endpoints before and after remediation.

Affected Versions

  • Oracle Application Testing Suite 13.3.0.1 — vulnerable
  • Oracle Application Testing Suite versions prior to the first Oracle-fixed release — assume vulnerable until confirmed by vendor advisory
  • TODO: insert fixed version from Oracle advisory — safe after upgrade

Note: Oracle has not provided a public fixed version in the context supplied here. Replace the TODO above with the exact patched release from the vendor advisory before publishing internally.

Resolution Guide

There is no npm/pip/Maven package to upgrade here; this is a vendor product patch. For solo developers and small teams, the fastest safe path is: isolate, patch, verify, then restore access narrowly.

# 1) Identify the host and version
# Linux examples
grep -R "13.3.0.1" /opt/oracle /u01 2>/dev/null
find /opt/oracle -maxdepth 3 -type f \( -name "*version*" -o -name "*.properties" \) -print

# 2) Temporarily restrict network access (example with ufw)
sudo ufw deny from any to any port <TODO_TCP_PORT>
sudo ufw allow from <ADMIN_IP> to any port <TODO_TCP_PORT>

# 3) Stop the service before patching
sudo systemctl stop <TODO_SERVICE_NAME>

# 4) Apply Oracle patch / upgrade package
# TODO: replace with the exact Oracle patch command or installer path
sudo /path/to/oracle-installer --apply-patch <TODO_PATCH_ID>

# 5) Start the service
sudo systemctl start <TODO_SERVICE_NAME>

Docker: if you run the suite in a container, do not keep using the old image tag.

# Pull the patched image once Oracle publishes it
docker pull <vendor>/application-testing-suite:<TODO_FIXED_TAG>

# Redeploy with the new tag
docker stop ats
docker rm ats
docker run -d --name ats -p <TODO_PORT>:<TODO_PORT> <vendor>/application-testing-suite:<TODO_FIXED_TAG>

Hardening examples:

# Example: bind only to localhost or a private interface if supported
# TODO: adjust to your product config file
listen_address=127.0.0.1
allowed_hosts=10.0.0.0/8,192.168.0.0/16

# Example: disable remote admin exposure if the suite supports it
remote_admin=false

Minimal rollback plan: if the patch fails, restore the pre-patch snapshot, keep the service isolated, and continue using a jump host only until Oracle confirms a compatible fix.

Detection & Verification

Check whether you are vulnerable:

# Find installed version strings
strings /path/to/oracle/binaries/* 2>/dev/null | grep -E "13\.3\.0\.1|Application Testing Suite"

# Search install metadata
grep -R "13.3.0.1" /opt/oracle /etc 2>/dev/null

# If you use a package inventory tool
rpm -qa | grep -i oracle
dpkg -l | grep -i oracle

Verify network exposure:

# Check listening ports
ss -lntp | grep -i oracle

# Confirm only approved sources can reach the service
sudo ufw status verbose
sudo iptables -S

Verify the fix:

# Confirm the version changed to the patched release
grep -R "TODO_FIXED_VERSION" /opt/oracle 2>/dev/null

# Re-run vulnerability scans / inventory checks
# Examples:
# - your SCA or asset inventory tool
# - Oracle patch inventory / installer logs
# - internal port scan from a trusted host

Log review: look for unexpected authentication attempts, unusual admin actions, new accounts, config changes, or spikes in requests to the suite’s TCP port before patching. If you have a SIEM, query for the product host plus the relevant port and any 4xx/5xx bursts or repeated connection attempts.

Risk and Impact

Successful exploitation can give an attacker full control of Oracle Application Testing Suite, including access to test assets, credentials, configuration, and any connected systems. In a small team, that can mean leaked secrets, tampered test results, broken CI pipelines, and a foothold into broader internal infrastructure.

Because the flaw is unauthenticated and network-reachable, the blast radius depends mainly on how exposed the service is. If the suite is reachable from shared office networks, VPNs, or cloud subnets, treat it as a high-priority incident response item until patched and access-restricted.

Keep reading