Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle Helidon 3.0.0‑3.2.17's Imperative Web Server permits an unauthenticated attacker with network access over HTTPS to read a subset of data exposed by the server; the issue is a weakness identified as CWE‑284 (Improper Authorization). Attackers can obtain confidential information through the web interface without needing credentials, leading to a confidentiality breach, and the flaw does not affect integrity or availability. This vulnerability allows unauthenticated access to sensitive data via the HTTPS interface.

Affected Systems

Oracle Helidon 3.0.0 through 3.2.17, distributed as part of Oracle Fusion Middleware, are affected. Only versions prior to 3.2.18 contain the flaw.

Risk and Exploitability

CVSS 3.1 base score 5.3 reflects moderate confidentiality impact. EPSS score below 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Any entity that can reach the Helidon instance over HTTPS can trigger the exploit without credentials or prior compromise, allowing them to read a limited set of data.

Generated by OpenCVE AI on August 29, 2026 at 02:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Helidon to version 3.2.18 or later to patch the vulnerability.
  • Restrict external HTTPS access to the Helidon service by using firewall rules or a reverse proxy to limit connections to trusted networks.
  • If an upgrade is not immediately possible, disable any unused endpoints or gracefully shut down the Helidon service to reduce exposed data.
  • Monitor Helidon logs for abnormal HTTPS access patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on August 29, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Data Exposure in Oracle Helidon

Sat, 29 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTPS Data Disclosure in Oracle Helidon 3.2.18
Weaknesses CWE-200

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTPS Data Disclosure in Oracle Helidon 3.2.18
Weaknesses CWE-200
CWE-284

Fri, 21 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Data Read in Oracle Helidon 3.2.18
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS Data Read in Oracle Helidon 3.2.18
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:33:47.833Z

Reserved: 2026-08-04T22:06:34.592Z

Link: CVE-2026-70727

cve-icon Vulnrichment

Updated: 2026-08-25T15:25:25.561Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:17:25.260

Modified: 2026-08-28T20:19:43.260

Link: CVE-2026-70727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T03:00:02Z

Weaknesses