Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18 and 3.0.0-3.2.17. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Helidon’s Imperative Web Server contains a vulnerability that enables a low-privilege attacker with network access via HTTP to compromise the application. The flaw is difficult to exploit, as indicated by a high attack complexity factor, yet it remains achievable for an attacker possessing only basic network connectivity. Successful exploitation results in a complete takeover, violating confidentiality, integrity, and availability; the CVSS 3.1 base score of 7.5 reflects this high severity. The listed CWE-284 identifier points to a potential improper access control weakness, although the root cause is not explicitly detailed in the description.

Affected Systems

Affected Oracle Helidon versions span 1.0.0 through 1.4.18 and 3.0.0 through 3.2.17. Versions beyond 3.2.17, such as 3.2.18, are not affected. Helidon is part of Oracle Fusion Middleware and is delivered under the Helidon brand.

Risk and Exploitability

The vulnerability is network-based (AV:N) with a high attack complexity (AC:H) and requires low privileges (PR:L). Its impact on confidentiality, integrity, and availability (C:H/I:H/A:H) is high, matching the CVSS base score of 7.5. The EPSS score is reported as less than 1%, indicating a low overall likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. The identified weakness (CWE-284) suggests improper access control as a possible root; however, the specific attack surface or vulnerable component is not detailed in the description.

Generated by OpenCVE AI on August 28, 2026 at 20:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch update that addresses Helidon 3.2.18 as indicated in the security alert
  • Restrict inbound HTTP traffic to Helidon services to only trusted hosts or VPN segments
  • Disable or remove any unused HTTP endpoints or services that expose the Helidon application

Generated by OpenCVE AI on August 28, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Low-Privilege HTTP Vulnerability Enabling Takeover

Fri, 28 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18 and 3.0.0-3.2.17. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server: Low-Privilege Network Exploitation Leading to Full Takeover

Thu, 20 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server: Low-Privilege Network Exploitation Leading to Full Takeover

Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Low‑Privilege HTTP Exploitation Leading to Full Takeover
Weaknesses CWE-732

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Low‑Privilege HTTP Exploitation Leading to Full Takeover
Weaknesses CWE-284
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T04:37:43.254Z

Reserved: 2026-08-04T22:06:34.621Z

Link: CVE-2026-71160

cve-icon Vulnrichment

Updated: 2026-08-19T14:28:02.796Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:17.330

Modified: 2026-08-28T05:16:44.183

Link: CVE-2026-71160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:15:06Z

Weaknesses