Impact
The vulnerability resides in Oracle’s Helidon Fusion Middleware Imperative Web Server component. Versions 3.0.0-3.2.17 and 4.0.0-4.4.1 are affected. An unauthenticated attacker who can reach Helidon over HTTP can read a subset of data accessible by the server, compromising confidentiality. The weakness can be classified as inappropriate exposure of information and authorization issues, underlying CWE 284.
Affected Systems
The affected product is Oracle Helidon, versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1. These supported releases are listed in the Oracle CSPU August 2026 advisory. Systems running any of these builds are susceptible to the described read access flaw.
Risk and Exploitability
The CVSS base score of 5.3 reflects a moderate confidentiality impact. EPSS indicates a probability of less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting a very low likelihood of exploitation. Because the flaw allows unauthenticated exploitation over a network HTTP endpoint, an attacker with network reach can mount a simple request to obtain data without prior credentials. The lack of authentication means the attack can be automated and requires no special privileges.
OpenCVE Enrichment