Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helidon product of Oracle Fusion Middleware provides an Imperative Web Server that contains a flaw allowing unauthenticated attackers to read a subset of data exposed over HTTP. The vulnerability is a breach of authorization, as indicated by CWE-284, and results in information disclosure. The affected version range ends at 3.2.17, so newer releases such as 3.2.18 are not impacted.

Affected Systems

Oracle Helidon versions 3.0.0 through 3.2.17 are affected. The product is part of Oracle Fusion Middleware and can be deployed in environments where the Helidon HTTP endpoint is reachable over the network.

Risk and Exploitability

The CVSS 3.1 base score of 5.3 classifies the issue as moderate severity with a confidentiality impact. The vector indicates a network‑based attack, low complexity, no privileges, and no user interaction, rendering the flaw easily exploitable if the Helidon service is exposed. The EPSS score is reported as < 1%, suggesting a low overall probability of exploitation in general populations; the vulnerability is not included in CISA’s KEV catalog. Attackers on the same network segment or who can reach the Helidon endpoint can leverage the flaw without additional credentials to obtain sensitive data exposed by the server.

Generated by OpenCVE AI on August 29, 2026 at 00:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch by upgrading Helidon to a version released after 3.2.17 that fixes the authentication bypass.
  • Consider disabling or restricting the Helidon HTTP endpoints so that only trusted hosts can reach them.
  • Review firewall or network segmentation rules to limit exposure of the Helidon service to trusted networks.

Generated by OpenCVE AI on August 29, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Disclosure in Oracle Helidon 3.2.18

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Disclosure in Oracle Helidon 3.2.18

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Information Disclosure in Oracle Helidon 3.2.18
Weaknesses CWE-200
CWE-284

Thu, 20 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Information Disclosure in Oracle Helidon 3.2.18
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Read Access via HTTP in Oracle Helidon Web Server
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Read Access via HTTP in Oracle Helidon Web Server
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:23:33.575Z

Reserved: 2026-08-13T18:41:45.881Z

Link: CVE-2026-73871

cve-icon Vulnrichment

Updated: 2026-08-20T18:11:05.215Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:19.333

Modified: 2026-08-28T20:19:45.840

Link: CVE-2026-73871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses