Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19 and 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle Helidon (versions 1.0.0 through 1.4.19, and 3.0.0 through 3.2.17) that allows an unauthenticated network attacker to send HTTP requests and compromise the Helidon service. A successful exploitation results in a full takeover of the Helidon instance, providing the attacker with full confidentiality, integrity, and availability impact as reflected in the CVSS 3.1 base score of 9.8.

Affected Systems

The affected product is Oracle Helidon, specifically the Imperative Web Server component of Oracle Fusion Middleware. Versions 1.0.0 through 1.4.19 and 3.0.0 through 3.2.17 are affected. No other versions beyond those ranges are listed as vulnerable.

Risk and Exploitability

The CVSS score indicates a high likelihood of severe impact. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and the EPSS score is 0.00473 (approximately 0.47%), indicating a very low but nonzero exploitation probability. Based on the description, the attack vector is a network-based HTTP request accepted without authentication, enabling an attacker to trigger the remote code execution that leads to system takeover.

Generated by OpenCVE AI on August 28, 2026 at 20:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that addresses the Helidon 3.2.18 vulnerability as soon as it becomes available.
  • If a patch cannot be deployed immediately, block all external network traffic to the Helidon service or restrict it to trusted IP addresses using firewall rules or network segmentation.
  • Disable or remove the Imperative Web Server component if it is not required for your deployment, or ensure it is isolated from untrusted users.

Generated by OpenCVE AI on August 28, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Helidon Imperative Web Server

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19 and 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Helidon Improper Access Control Allows Remote Code Execution and System Takeover

Wed, 19 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Helidon Improper Access Control Allows Remote Code Execution and System Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-27T21:32:12.316Z

Reserved: 2026-08-04T22:06:34.615Z

Link: CVE-2026-71074

cve-icon Vulnrichment

Updated: 2026-08-19T15:08:02.850Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:07.503

Modified: 2026-08-28T00:18:08.790

Link: CVE-2026-71074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:00:04Z

Weaknesses