Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Helidon product of Oracle Fusion Middleware’s imperative web server component allows an unauthenticated HTTP attacker to modify, insert, or delete data and to read a subset of accessible data. Successful attacks require human interaction from a person other than the attacker and may impact additional products. The flaw affects Helidon versions 4.0.0 through 4.4.1 and can lead to integrity and confidentiality breaches due to lack of proper access controls.

Affected Systems

Oracle Helidon, versions 4.0.0 through 4.4.1, in Oracle Fusion Middleware. These releases are affected; later releases are not listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 6.1 indicates moderate severity with low confidentiality and integrity impact. EPSS score < 1% indicates an extremely low but non-zero probability of exploitation and the vulnerability is not listed in the CISA KEV catalog. Attackers exploit the flaw via unauthenticated HTTP traffic; however, the description indicates that successful attacks require human interaction from a person other than the attacker, suggesting possible social engineering or gateway involvement. The scope may change because successful exploitation in Helidon may affect other products running in the same environment.

Generated by OpenCVE AI on August 29, 2026 at 00:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Helidon to a non‑affected version or apply any vendor‑issued patch that addresses the authentication bypass.
  • Restrict external HTTP access to Helidon by placing it behind a firewall or VPN so only trusted networks can reach it.
  • Enforce application‑level authorization checks to limit who can read, modify, or delete data, mitigating impact if the flaw is leveraged.
  • Monitor application logs for anomalous DML or read operations and alert on unauthorized activity.

Generated by OpenCVE AI on August 29, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification and Read in Oracle Helidon 4.5.0
Weaknesses CWE-200

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification and Read in Oracle Helidon 4.5.0
Weaknesses CWE-200
CWE-284

Thu, 20 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Allows Unauthorized Data Access in Oracle Helidon 4.5.0
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Allows Unauthorized Data Access in Oracle Helidon 4.5.0
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Helidon 4.5.0 Leading to Unauthorized Data Modification
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Vulnerability in Oracle Helidon 4.5.0 Leading to Unauthorized Data Modification
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:01:58.083Z

Reserved: 2026-08-13T18:41:45.881Z

Link: CVE-2026-73870

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:43.569Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:19.220

Modified: 2026-08-28T20:19:45.730

Link: CVE-2026-73870

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses