Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the updated CVE description, the Helidon component of Oracle Fusion Middleware contains a flaw in its Imperative Web Server that allows an unauthenticated attacker with HTTP network access to compromise the application. Versions 3.0.0 through 3.2.17 are affected. A successful exploitation can lead to unauthorized access to critical data, complete access to all Helidon‑served data, and unauthorized update, insert or delete operations on some Helidon data. The CVSS base score of 8.2 indicates high impact on confidentiality and integrity. The vulnerability stems from an authentication and authorization weakness, identified as CWE-284.

Affected Systems

Oracle Helidon versions 3.0.0 through 3.2.17, part of Oracle Fusion Middleware's Imperative Web Server, are affected. No later versions are listed.

Risk and Exploitability

Based on the updated description, it is inferred that the likely attack vector is via unauthenticated HTTP requests from any network location. The vulnerability has a high severity score of 8.2 and can be exploited from any network location with HTTP access, with no required authentication or user interaction. The EPSS score of <1% indicates a very low probability of exploitation, yet the easily exploitable nature and the potential for broad data compromise make it a significant risk. The vulnerability is not yet listed in the CISA KEV catalog, but the impact and low attack barrier warrant immediate attention.

Generated by OpenCVE AI on August 28, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Helidon to a patched or later version that removes the flaw
  • Block or restrict external HTTP traffic to Helidon services until a patch is applied
  • Enable and review audit logging on Helidon to detect any unauthorized access attempts

Generated by OpenCVE AI on August 28, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access in Oracle Helidon Imperative Web Server

Fri, 28 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Unauthenticated Data Access Vulnerability

Thu, 20 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Unauthenticated Data Access Vulnerability

Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Helidon 3.2.18
Weaknesses CWE-287

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Helidon 3.2.18
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T04:28:42.070Z

Reserved: 2026-08-04T22:06:34.621Z

Link: CVE-2026-71159

cve-icon Vulnrichment

Updated: 2026-08-19T14:24:18.226Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:17.167

Modified: 2026-08-28T05:16:44.067

Link: CVE-2026-71159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:30:08Z

Weaknesses