Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helidon Imperative Web Server component of Oracle Helidon contains an easily exploitable flaw that allows a low‑privileged attacker with network access via HTTP to gain unauthorized update, insert, or delete rights on data exposed by the service, as well as read access to a subset of that data. Consequently, confidentiality and integrity of Helidon‑managed data are compromised, while availability remains unaffected.

Affected Systems

This vulnerability affects Oracle Helidon versions 3.0.0 through 3.2.17, which are part of Oracle Fusion Middleware. The flaw is present when the Helidon Imperative Web Server is exposed over HTTP. No other Oracle Helidon releases or related products are known to be impacted.

Risk and Exploitability

The CVSS v3.1 base score of 5.4 indicates moderate severity, with low attack complexity, low required privileges, and no user interaction. The EPSS score of < 1% and absence from the CISA KEV catalog suggest that exploitation risk is largely driven by the ease of sending crafted HTTP requests to a non‑authenticated endpoint that lacks proper access control. A threat actor could send HTTP requests targeting the vulnerable endpoint to obtain unauthorized data manipulation and read permissions, thereby violating confidentiality and integrity.

Generated by OpenCVE AI on August 29, 2026 at 00:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch or upgrade to a non‑vulnerable revision of Oracle Helidon as released by Oracle.
  • If an upgrade is not immediately possible, restrict external network access to the Helidon service by applying firewall rules or network segmentation to limit connections to trusted hosts only.
  • Enforce strict authentication and role‑based access controls for all Helidon endpoints, ensuring that only authorized users can perform update, insert, or delete operations.
  • Enable and monitor logging for unauthorized data access attempts to detect potential exploitation early.

Generated by OpenCVE AI on August 29, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Low-Privileged HTTP Attack in Oracle Helidon Imperative Web Server

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Access Control Bypass in Helidon Imperative Web Server

Thu, 20 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Access Control Bypass in Helidon Imperative Web Server

Wed, 19 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Vulnerability Enabling Unauthorized Data Modifications over HTTP
Weaknesses CWE-693

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Vulnerability Enabling Unauthorized Data Modifications over HTTP
Weaknesses CWE-284
CWE-693

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:09:33.615Z

Reserved: 2026-08-04T22:06:34.621Z

Link: CVE-2026-71165

cve-icon Vulnrichment

Updated: 2026-08-19T14:26:09.577Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:17.820

Modified: 2026-08-28T20:19:44.220

Link: CVE-2026-71165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses