Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle Helidon’s Imperative Web Server component affects supported versions 4.0.0 through 4.5.0. A high‑privileged attacker who can log on to the infrastructure where Helidon runs can compromise the application. The weakness is an improper access control flaw (CWE‑284) that allows the attacker to bypass normal authorization checks and read any data exposed through Helidon, leading to a confidentiality breach.

Affected Systems

Oracle Helidon versions 4.0.0 through 4.5.0, part of Oracle Fusion Middleware, are affected by this vulnerability.

Risk and Exploitability

The CVSS 3.1 score of 4.4 indicates a moderate threat, primarily due to confidentiality impact. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local (AV:L) and requires an attacker to possess high‑level privileges on the infrastructure hosting Helidon. Once these prerequisites are met, the attacker can obtain unrestricted access to all data available through the Helidon instance.

Generated by OpenCVE AI on August 28, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to any Helidon version that has the fix and is not affected.
  • Limit local privileged access to the infrastructure hosting Helidon; enforce least‑privilege principles for any accounts that can log on to the host.
  • Review and reinforce application‑level access controls to ensure that data can only be accessed by authorized users.

Generated by OpenCVE AI on August 28, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Helidon Improper Access Control Vulnerability

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Tue, 25 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Helidon 4.5.1
Weaknesses CWE-862

Tue, 25 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Helidon 4.5.1
Weaknesses CWE-862

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Access in Oracle Helidon 4.5.1 Web Server
Weaknesses CWE-284

Thu, 20 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Access in Oracle Helidon 4.5.1 Web Server
Weaknesses CWE-284

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Helidon 4.5.1 allows high privileged local attacker to obtain critical data
Weaknesses CWE-284

Wed, 19 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Helidon 4.5.1 allows high privileged local attacker to obtain critical data
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:35:47.165Z

Reserved: 2026-08-13T18:41:45.882Z

Link: CVE-2026-73880

cve-icon Vulnrichment

Updated: 2026-08-25T01:30:46.491Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:20.393

Modified: 2026-08-28T20:19:46.620

Link: CVE-2026-73880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T22:00:15Z

Weaknesses