Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helidon Imperative Web Server component in Oracle Fusion Middleware version 4.5.0 contains a vulnerability that allows an unauthenticated attacker with network access to perform unauthorized creation, deletion or modification of data. The flaw can lead to both confidentiality and integrity violations, giving the attacker full control over all Helidon accessible data. The weakness is a lack of proper access control, as indicated by the high impact on confidentiality and integrity.

Affected Systems

Affected: Oracle Helidon 4.5.0, part of Oracle Fusion Middleware. No other versions are listed as vulnerable. The product is accessed over HTTP on the network.

Risk and Exploitability

The CVSS 3.1 base score of 7.4 reflects a medium‑to‑high severity risk. Exploitation requires network connectivity to the Helidon service and no user interaction, though the high attack complexity suggests the issue is difficult to exploit. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, indicating no confirmed active exploitation yet. Nevertheless, because the vulnerability permits full unauthorized data manipulation, it poses a serious threat to affected deployments.

Generated by OpenCVE AI on August 18, 2026 at 23:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Helidon update (4.5.1 or later) to eliminate the vulnerability.
  • If an upgrade cannot be applied immediately, restrict Helidon HTTP exposure to trusted networks or block the port for external hosts.
  • Review and enforce proper access‑control configuration on the Helidon web server, ensuring that authentication and authorization checks are active for all endpoints.

Generated by OpenCVE AI on August 18, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Modification in Oracle Helidon Imperative Web Server
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:20.579Z

Reserved: 2026-07-08T15:51:55.601Z

Link: CVE-2026-60915

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:47.460

Modified: 2026-08-18T21:16:47.460

Link: CVE-2026-60915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:30:04Z

Weaknesses