Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A difficult‑to‑exploit flaw exists in Oracle Helidon’s Imperative Web Server that permits an unauthenticated attacker with HTTP network access to compromise the server. The vulnerability enables the attacker to read critical data or gain full access to any data that the Helidon instance makes available. The issue is an authorization bypass that changes scope, potentially affecting additional applications that rely on Helidon.

Affected Systems

Oracle Helidon versions 3.0.0 through 3.2.17 are affected. The Helidon product is part of Oracle Fusion Middleware and the flaw resides in its web server component.

Risk and Exploitability

The CVSS v3.1 base score of 6.8 indicates a moderate severity, with a network attack vector, high complexity, no required privileges, and no user interaction, while changing scope to affect confidentiality. The EPSS score is below 1 % and the issue is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is remote HTTP access, allowing potential unauthorized data exposure if the vulnerability is reached.

Generated by OpenCVE AI on August 29, 2026 at 00:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest patched Oracle Helidon release as announced in Oracle’s security advisory.
  • Limit external HTTP exposure by applying firewall rules or network segmentation so only trusted IP addresses can reach the Helidon server.
  • Continuously monitor Helidon logs and network traffic for abnormal activity or repeated failed requests that could indicate probing or exploitation attempts.

Generated by OpenCVE AI on August 29, 2026 at 00:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Unauthorized Data Access via HTTP

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:* cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access to Oracle Helidon 3.2.18 via Imperative Web Server

Thu, 20 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access to Oracle Helidon 3.2.18 via Imperative Web Server

Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Helidon Unauthorized Access via HTTP in Imperative Web Server
Weaknesses CWE-200
CWE-285

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Helidon Unauthorized Access via HTTP in Imperative Web Server
Weaknesses CWE-200
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T17:36:59.870Z

Reserved: 2026-08-04T22:06:34.612Z

Link: CVE-2026-71029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:02.493

Modified: 2026-08-31T12:31:56.150

Link: CVE-2026-71029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:30:17Z

Weaknesses