Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Helidon’s Imperative Web Server component of Oracle Fusion Middleware permits an unauthenticated attacker with network access over HTTP to read protected data. The vulnerability is effective on Helidon versions 3.0.0 through 3.2.19 and is not present in 3.2.20 or newer. As a result, an attacker can gain unauthorized read access to a subset of resources managed by Helidon, impacting confidentiality but not affecting integrity or availability.

Affected Systems

The flaw affects Oracle Helidon, specifically the Helidon Imperative Web Server component in Oracle Fusion Middleware. Supported versions that are vulnerable are 3.0.0 through 3.2.19; versions 3.2.20 and later are not affected.

Risk and Exploitability

The CVSS v3.1 base score of 3.7 indicates a low overall risk, with only confidentiality impact. The EPSS score is less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a direct network reachability via an HTTP interface exposed to the attacker. No local access or privilege escalation is required. Given the low severity, the probability of exploitation is presumably low, but the vulnerability remains a potential risk for systems that expose Helidon services to untrusted networks.

Generated by OpenCVE AI on August 28, 2026 at 21:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Helidon update that addresses this issue (or upgrade to a non‑affected version).
  • Restrict HTTP access to the Helidon instance by firewalling or placing it behind an authentication gateway so that only trusted internal clients can reach it.
  • Consider disabling or hardening the Imperative Web Server endpoints that are not required for your deployment to reduce the exposed surface area.

Generated by OpenCVE AI on August 28, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Allows Unauthorized Data Read via HTTP

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Read via HTTP in Oracle Helidon 3.2.20
Weaknesses CWE-284

Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Read via HTTP in Oracle Helidon 3.2.20
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.20:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:37:06.008Z

Reserved: 2026-07-08T15:51:55.596Z

Link: CVE-2026-60853

cve-icon Vulnrichment

Updated: 2026-08-21T14:08:15.323Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:45.140

Modified: 2026-08-28T20:19:05.367

Link: CVE-2026-60853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T22:00:15Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor