Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17 and 4.0.0-4.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Published: 2026-08-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Helidon Imperative Web Server allows unauthenticated HTTP requests to create, delete, or modify critical data that the server manages. The vulnerability results in a high integrity impact, as it enables an attacker to alter or remove information without authorization. It is classified as a missing authorization weakness (CWE-284) and could lead to unauthorized manipulation of application data.

Affected Systems

Oracle Helidon, versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1 are impacted. These releases include the Imperative Web Server component where the flaw resides.

Risk and Exploitability

The CVSS v3.1 Base Score of 5.9 indicates a moderate severity primarily affecting integrity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated HTTP requests that can be sent from any network with access to the Helidon HTTP interface, requiring no authentication but necessitating legitimate HTTP traffic. If exploitation succeeds, an attacker could modify or delete any data processed by the server.

Generated by OpenCVE AI on August 29, 2026 at 00:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a Helidon release that contains the fix for CVE-2026-70716, ensuring that the affected version ranges (3.0.0-3.2.17, 4.0.0-4.4.1) are updated.
  • Limit HTTP access to the Helidon server so that only trusted internal hosts or IP ranges can reach its endpoints, using firewalls, network segmentation, or proxy controls.
  • Enable comprehensive logging of all write or modify operations performed by Helidon and configure monitoring alerts to detect anomalous activity that may indicate exploitation attempts.

Generated by OpenCVE AI on August 29, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification via HTTP in Oracle Helidon

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17 and 4.0.0-4.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification via HTTP in Oracle Helidon

Tue, 25 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leads to Unauthorized Data Modification in Oracle Helidon Web Server
Weaknesses CWE-285

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Leads to Unauthorized Data Modification in Oracle Helidon Web Server
Weaknesses CWE-285

Fri, 21 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Helidon
Weaknesses CWE-284

Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Helidon
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:07:47.107Z

Reserved: 2026-08-04T22:06:34.591Z

Link: CVE-2026-70716

cve-icon Vulnrichment

Updated: 2026-08-25T15:00:28.741Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:23.957

Modified: 2026-08-28T20:19:43.137

Link: CVE-2026-70716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:30:17Z

Weaknesses