Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Helidon, an Oracle Fusion Middleware component that hosts an Imperative Web Server, has an access control flaw that allows an unauthenticated attacker with network reach to the HTTP interface to create, delete, or modify any data the Helidon process can access. This results in a total loss of confidentiality and integrity for all Helidon‑served data, as the attacker can view or alter every piece of information exposed by the service.

Affected Systems

Oracle Helidon versions 4.0.0 through 4.4.1 are listed as vulnerable in the advisory. No other products or versions are mentioned, and the CPE data confirms that Helidon 4.5.0 is a separate variant not included in the affected range.

Risk and Exploitability

The flaw is remotely exploitable via ordinary HTTP traffic; the attacker needs only network access to the Helidon instance, with no authentication or privilege required. The EPSS score of less than 1% indicates that widespread exploitation is currently unlikely, but the absence of authentication means that once an attacker can reach the service, the attack can be carried out with minimal effort. The CVSS base score of 9.1 highlights a severe impact on confidentiality and integrity, and the vulnerability is not listed in the CISA KEV catalog, so organizations must assess and mitigate the risk themselves.

Generated by OpenCVE AI on August 28, 2026 at 21:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure Helidon to require authentication on all HTTP endpoints, ensuring that only authorized clients can perform operations (addressing CWE-284).
  • Limit inbound traffic to Helidon services by firewalling or using a reverse proxy that permits only trusted IP ranges.
  • Apply the latest Oracle patches or updates that fix the access control vulnerability as soon as they are released.
  • Enable detailed logging for access attempts and monitor logs for unauthenticated or suspicious requests, applying rate limiting or blocking when necessary.

Generated by OpenCVE AI on August 28, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Control Vulnerability in Oracle Helidon 4.5.0

Fri, 28 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Control Vulnerability in Oracle Helidon 4.5.0

Thu, 20 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Control Exploitation in Oracle Helidon Imperative Web Server

Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Control Exploitation in Oracle Helidon Imperative Web Server

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Helidon Unauthenticated Remote Data Access via Access Control Flaw

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Helidon Unauthenticated Remote Data Access via Access Control Flaw
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T04:13:21.762Z

Reserved: 2026-08-13T18:41:45.881Z

Link: CVE-2026-73866

cve-icon Vulnrichment

Updated: 2026-08-19T14:27:27.077Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:18.763

Modified: 2026-08-28T05:16:44.543

Link: CVE-2026-73866

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:45:03Z

Weaknesses