Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server) affects supported versions 3.0.0 through 3.2.17. The flaw allows an unauthenticated attacker with network access via HTTP to compromise Helidon. Successful exploitation can result in takeover of the Helidon instance, compromising confidentiality, integrity, and availability. The vulnerability is categorized as CWE-284.

Affected Systems

Affected product is Oracle Helidon, with affected versions 3.0.0 through 3.2.17. No other products or versions are listed as impacted.

Risk and Exploitability

The CVSS 3.1 base score of 9.8 and the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H highlight a critical risk, reachable over the network with low attack complexity. The EPSS score of less than 1% indicates that real‑world exploitation is currently rare, but the absence of authentication and public exposure of the HTTP interface elevate its practical danger. The vulnerability is not listed in CISA’s KEV catalog, which does not negate the need for remediation.

Generated by OpenCVE AI on August 28, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict inbound HTTP traffic to Helidon via firewall or network segmentation to eliminate unauthenticated access.
  • Monitor Helidon logs and network traffic for anomalous HTTP requests that could indicate an attempted exploitation.
  • Check the vendor’s website for updates or patches for Helidon 3.2.18.

Generated by OpenCVE AI on August 28, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Oracle Helidon 3.2.18 Improper Access Control Exposes Service to Remote Takeover

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Oracle Helidon 3.2.18 Improper Access Control Exposes Service to Remote Takeover

Thu, 20 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploitation Allows Full Helidon Takeover via Web Server

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploitation Allows Full Helidon Takeover via Web Server

Wed, 19 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Helidon 3.2.18
Weaknesses CWE-200

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Helidon 3.2.18
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-27T21:36:03.720Z

Reserved: 2026-08-04T22:06:34.621Z

Link: CVE-2026-71164

cve-icon Vulnrichment

Updated: 2026-08-19T14:27:31.853Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:17.703

Modified: 2026-08-28T00:18:09.033

Link: CVE-2026-71164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:30:08Z

Weaknesses