Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Helidon's Imperative Web Server allows a low‑privileged attacker who has logged onto the host where Helidon runs to compromise the service. Successfully exploiting the vulnerability can grant unauthorized access to critical data or all data exposed by Helidon, as well as permitting unauthorized update, insert or delete operations on that data.

Affected Systems

Oracle Helidon versions 4.0.0 through 4.4.1 are affected. No other releases are listed as vulnerable.

Risk and Exploitability

The Core Vulnerability Severity Score of 6.1 indicates moderate risk. The attack vector is local (AV:L), requiring low attack complexity (AC:L) and low privileges (PR:L) with no user interaction needed. The EPSS score of less than 1% signals a very low but non‑zero likelihood of exploitation. Because the flaw is not cataloged in CISA KEV, there are no known widespread attacks at this time. However, an attacker who has physical or remote console access to the Helidon host could leverage the vulnerability to read or modify Helidon‑exposed data, providing a clear, actionable threat for systems where Helidon runs under users with insufficiently restricted privileges.

Generated by OpenCVE AI on August 29, 2026 at 00:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review Oracle's security advisory for available updates or patches
  • Restrict host logon rights to trusted personnel and enforce least‑privilege for accounts that can run Helidon, limiting local user access to the Helidon process
  • Implement application‑level access controls so that Helidon only exposes data to authorized roles and sessions, blocking unauthorized read, write, or delete operations

Generated by OpenCVE AI on August 29, 2026 at 00:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Local Access Control Vulnerability

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Local Access Control Vulnerability

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 20 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Title Local access control flaw in Oracle Helidon 4.5.0
Weaknesses CWE-284

Thu, 20 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local access control flaw in Oracle Helidon 4.5.0
Weaknesses CWE-284

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Access Control Vulnerability in Oracle Helidon 4.5.0
Weaknesses CWE-284

Wed, 19 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Local Access Control Vulnerability in Oracle Helidon 4.5.0
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:06:19.262Z

Reserved: 2026-08-04T22:06:34.620Z

Link: CVE-2026-71154

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:39.538Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:16.510

Modified: 2026-08-28T20:19:43.640

Link: CVE-2026-71154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:30:17Z

Weaknesses