Impact
A vulnerability exists in Oracle Helidon’s Imperative Web Server across multiple major releases, specifically versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1. The flaw permits any unauthenticated user with network access via standard HTTP to execute arbitrary code on the Helidon instance, enabling full takeover of the server. Successful exploitation compromises confidentiality, integrity, and availability of the affected environment.
Affected Systems
Oracle Helidon versions 3.0.0‑3.2.17 and 4.0.0‑4.4.1 are affected. No other Oracle Fusion Middleware products are currently listed as impacted.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity, and the EPSS score of less than 1% shows a very low but non-zero likelihood that the vulnerability will be exploited. The flaw is not listed in CISA’s KEV catalog. Attackers can exploit the flaw remotely over standard HTTP without authentication, making it easily actionable for network-visible instances of Helidon.
OpenCVE Enrichment