Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Imperative Web Server of Oracle Helidon versions 4.0.0 through 4.4.1 permits an attacker who can reach the HTTP interface to alter or read Helidon data without proper authorization. The attacker does not need a user interface or elevated credentials; merely low‑privileged network access suffices to send crafted HTTP requests that bypass the access controls, resulting in confidentiality and integrity impacts.

Affected Systems

Oracle Helidon versions 4.0.0 through 4.4.1 in Oracle Fusion Middleware are the affected assets. The vulnerability resides in the Imperative Web Server component and can be exploited by any host able to connect to the Helidon HTTP endpoint.

Risk and Exploitability

The base CVSS score of 5.4 indicates moderate severity, with low but measurable confidentiality and integrity impact and no availability impact. The EPSS score is below 1 %, implying a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread, actively exploited instances are known. The attack vector is over the network via HTTP, requiring only low‑privileged access, which makes the flaw easily exploitable by any threat actor able to send crafted requests to Helidon.

Generated by OpenCVE AI on August 28, 2026 at 23:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Helidon to a version newer than 4.4.1 or apply any available vendor patch that fixes the access‑control flaw
  • Restrict the Helidon HTTP endpoint to trusted hosts or networks, for example by enforcing firewall rules or a VPN
  • Enforce strict least‑privilege access controls on all Helidon user accounts to limit the impact of potential data modification

Generated by OpenCVE AI on August 28, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification via HTTP in Oracle Helidon 4.5.0

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Data Modification via HTTP in Oracle Helidon 4.5.0
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:10:25.916Z

Reserved: 2026-08-13T18:41:45.882Z

Link: CVE-2026-73874

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:47.444Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:19.693

Modified: 2026-08-28T20:19:46.173

Link: CVE-2026-73874

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:45:03Z

Weaknesses