Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Helidon versions 3.0.0 through 3.2.18, within the Imperative Web Server component, permits an unauthenticated attacker to reach the web server over HTTP and modify data stored by the application. This lack of authentication and authorization control, corresponding to CWE-284, allows direct alteration of protected data. The vulnerability is exercised through HTTP requests that do not require any authentication, and successful exploitation grants the attacker the ability to update, insert or delete protected data, impacting the integrity of the system. The CVSS 3.1 base score of 5.3 reflects a moderate difficulty to exploit and an impact limited to data integrity, with no confidentiality or availability impact. The CVSS vector indicates an network attack vector, low attack complexity, no privileges or user interaction, and an overall unchanged scope.

Affected Systems

Oracle Corporation Helidon Fusion Middleware versions 3.0.0 through 3.2.18 are affected. No additional vendor or product versions are listed in the vulnerability report.

Risk and Exploitability

The CVSS score of 5.3 positions this issue in the moderate severity range, and the EPSS score of <1% indicates a very low likelihood of public exploitation. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is over the network via HTTP, where an attacker can craft and send requests without any form of authentication, exploiting the missing access control. Successful attacks can lead to unauthorized data modification, compromising business processes and data integrity.

Generated by OpenCVE AI on August 29, 2026 at 01:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Helidon release that includes the fix for access control in all HTTP endpoints, addressing CWE-284.
  • Configure Helidon to enforce authentication and authorization on all exposed endpoints, ensuring only authenticated users can modify data.
  • Enable audit logging for all data modification operations and set up real‑time alerts to detect unauthorized changes.

Generated by OpenCVE AI on August 29, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Helidon 3.2.19 Unauthenticated HTTP Access Allows Data Modification

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Helidon 3.2.19 Unauthenticated HTTP Access Allows Data Modification

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.19:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:14:04.754Z

Reserved: 2026-08-04T22:06:34.621Z

Link: CVE-2026-71156

cve-icon Vulnrichment

Updated: 2026-08-19T14:24:25.360Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:16.730

Modified: 2026-08-28T20:19:43.757

Link: CVE-2026-71156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T01:15:07Z

Weaknesses