Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Helidon, part of Oracle Fusion Middleware, suffered an improper access control flaw in its Imperative Web Server component. The vulnerability, documented as affecting versions 3.0.0 through 3.2.17, permits a low‑privileged attacker who can reach the server over HTTP to update, insert, delete, or read Helidon‑accessible data that should be protected. This flaw maps to CWE‑284 and results in confidentiality and integrity impacts as reflected by the CVSS vector, which shows low but non‑zero effects for both dimensions.

Affected Systems

Oracle Helidon versions 3.0.0 through 3.2.17 are affected. These releases are part of Oracle Fusion Middleware and are supported on the indicated version range; earlier and later versions are not known to be impacted.

Risk and Exploitability

The CVSS base score of 4.2 classifies the flaw as medium severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of active exploitation. The attack requires network reachability to the Helidon instance over HTTP and the ability to act with low privileges – for example, a local user or a compromised host. Successful exploitation enables an attacker to alter or read Helidon data, undermining business data integrity and confidentiality.

Generated by OpenCVE AI on August 29, 2026 at 00:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s website or security advisories for any available patch or update for Helidon 3.2.18 and apply it as soon as it becomes available.
  • Restrict HTTP access to the Helidon instance by configuring firewall rules or network segmentation so that only trusted IPs can reach the service.
  • Review and tighten role‑based access controls, ensuring that low‑privileged users do not have permissions that allow modification of Helidon resources.
  • Enable logging and set alerts for unauthorized modification attempts on Helidon data to detect and respond to potential exploitation.

Generated by OpenCVE AI on August 29, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Helidon 3.2.18

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Helidon 3.2.18
Weaknesses CWE-284

Thu, 20 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Oracle Helidon 3.2.18 Unauthorized Data Access via HTTP
Weaknesses CWE-284

Wed, 19 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Oracle Helidon 3.2.18 Unauthorized Data Access via HTTP
Weaknesses CWE-284

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Low-Privilege HTTP Access in Oracle Helidon
Weaknesses CWE-284

Wed, 19 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Low-Privilege HTTP Access in Oracle Helidon
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:36:25.048Z

Reserved: 2026-08-13T18:41:45.882Z

Link: CVE-2026-73873

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:45.521Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:19.577

Modified: 2026-08-28T20:19:46.063

Link: CVE-2026-73873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses