Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Helidon’s Imperative Web Server has a flaw that permits an unauthenticated network attacker with HTTP access to modify or read data without proper authorization. The vulnerability can lead to unauthorized updates, inserts or deletes, or reads of Helidon‑protected data, compromising confidentiality and integrity. The description of this vulnerability has been updated; consult the official advisory for the latest details.

Affected Systems

Oracle Helidon versions 3.0.0 through 3.2.17 are affected. No other products or extensions are listed as directly impacted, though the vulnerability may indirectly affect other applications that rely on Helidon services.

Risk and Exploitability

The CVSS v3.1 score of 6.1 indicates a moderate severity with moderate exploitation difficulty (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Exploitation requires network access via HTTP and a secondary human interaction, meaning an attacker alone cannot fully compromise the system without cooperation from another user. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog; thus no known public exploits or high exploit probability are reported at this time.

Generated by OpenCVE AI on August 29, 2026 at 00:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle for an available update or advisory for Helidon versions 3.0.0 through 3.2.17, and apply any fix if one exists.
  • Restrict HTTP access to Helidon endpoints to trusted internal networks and enforce authentication and authorization controls for exposed services.
  • Implement logging and monitoring of Helidon operations to detect unauthorized updates, inserts, deletes, or reads and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 29, 2026 at 00:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Unauthenticated HTTP Access in Oracle Helidon

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure in Oracle Helidon 3.2.18

Wed, 19 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure in Oracle Helidon 3.2.18
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:01:20.728Z

Reserved: 2026-08-13T18:41:45.881Z

Link: CVE-2026-73869

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:41.642Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:19.103

Modified: 2026-08-28T20:19:45.613

Link: CVE-2026-73869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:45:04Z

Weaknesses