Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17 and 4.0.0-4.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helidon Imperative Web Server component in Oracle Fusion Middleware, for versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1, contains a vulnerability that allows an unauthenticated attacker with network access via HTTP to perform unauthorized creation, deletion or modification of data. The flaw can lead to both confidentiality and integrity violations, giving the attacker full control over all Helidon accessible data.

Affected Systems

Affected: Oracle Helidon versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1, part of Oracle Fusion Middleware. The product is accessed over HTTP on the network.

Risk and Exploitability

The CVSS 3.1 base score of 7.4 reflects a medium‑to‑high severity risk. Exploitation requires network connectivity to the Helidon service over HTTP and no user interaction, though the high attack complexity indicates the issue is difficult to exploit. The EPSS score is less than 1%, and the flaw is not listed in the CISA KEV catalog, indicating no confirmed active exploitation yet. Nevertheless, because the vulnerability permits full unauthorized data manipulation, it poses a serious threat to affected deployments.

Generated by OpenCVE AI on August 29, 2026 at 00:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check with Oracle for an update or patch that addresses the vulnerability.
  • If an upgrade cannot be applied immediately, restrict Helidon HTTP exposure to trusted networks or block the port for external hosts.
  • Review and enforce proper access‑control configuration on the Helidon web server, ensuring that authentication and authorization checks are active for all endpoints.

Generated by OpenCVE AI on August 29, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Helidon Unauthenticated HTTP Bypass Enables Unauthorized Data Modification

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17 and 4.0.0-4.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Helidon Unauthenticated HTTP Bypass Enables Unauthorized Data Modification
Weaknesses CWE-284

Fri, 21 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Modification in Oracle Helidon Imperative Web Server
Weaknesses CWE-284

Tue, 18 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Modification in Oracle Helidon Imperative Web Server
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T17:24:32.521Z

Reserved: 2026-07-08T15:51:55.601Z

Link: CVE-2026-60915

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:16:47.460

Modified: 2026-08-28T20:19:05.903

Link: CVE-2026-60915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:30:17Z

Weaknesses