Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Helidon Imperative Web Server allows an unauthenticated attacker with network access via HTTP to read and potentially alter Helidon accessible data, affecting versions 3.0.0 through 3.2.17. The vulnerability enables unauthorized update, insert, or delete operations, thereby compromising the confidentiality and integrity of the data exposed by the web service. The weakness is an improper access control flaw (CWE‑284).

Affected Systems

Oracle Helidon versions 3.0.0 through 3.2.17 are affected by this CVE. Earlier and later releases are not reported as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates a moderate to high risk, and the attack scenario requires only a network connection to the HTTP endpoint. Exploit difficulty is high (acquisition of the vulnerability is not trivial), and the EPSS score is less than 1%, indicating a very low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no documented active exploits yet. Nevertheless, an unauthenticated attacker who can reach Helidon over HTTP can exploit this flaw, potentially leading to unauthorized data modification and exposure.

Generated by OpenCVE AI on August 28, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Helidon to a patched version that includes the fix for CVE-2026-71162.
  • If an immediate upgrade is not feasible, restrict external network access to the Helidon HTTP service via firewall rules or only permit access through a VPN.
  • Enforce proper authentication and access control on Helidon endpoints, ensuring that only authorized users can read or modify data.
  • Monitor Helidon logs for anomalous requests or signs of exploitation attempts.

Generated by OpenCVE AI on August 28, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control Vulnerability in Oracle Helidon Imperative Web Server

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Unauthorized Access and Data Modification Vulnerability

Thu, 20 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Unauthorized Access and Data Modification Vulnerability

Wed, 19 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification and Disclosure in Oracle Helidon

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification and Disclosure in Oracle Helidon
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T17:53:13.704Z

Reserved: 2026-08-04T22:06:34.621Z

Link: CVE-2026-71162

cve-icon Vulnrichment

Updated: 2026-08-19T14:26:11.927Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:17.580

Modified: 2026-08-28T20:19:44.107

Link: CVE-2026-71162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:45:03Z

Weaknesses