Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
Published: 2026-08-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Helidon Imperative Web Server allows attackers to perform unauthorized update, insert, delete, or read operations on data exposed by Helidon. The flaw, identified as an access control weakness, is exploitable without authentication over the network, leading to confidentiality and integrity compromise as reflected by the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N. Note: The official description was updated; the core details remain consistent with the prior assessment.

Affected Systems

Oracle Helidon versions 3.0.0 through 3.2.17 are affected by this vulnerability. The flaw is confined to Helidon but can affect other products that rely on it because of a scope change.

Risk and Exploitability

The CVSS score of 7.2 reflects moderate to high severity, the EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack path requires only HTTP network access to the Helidon service, enabling an unauthenticated attacker to manipulate or read protected data. Given the lack of defensive controls reported, the risk of exploitation remains significant.

Generated by OpenCVE AI on August 28, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Helidon to a non‑affected version or apply the vendor‑supplied patch
  • Restrict external HTTP access to Helidon through firewall rules or VPN, limiting exposure to trusted networks
  • Monitor Helidon logs for unexpected write or read activity and enforce strict access controls
  • If possible, disable or harden any unused endpoints or features exposed by Helidon

Generated by OpenCVE AI on August 28, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability in Oracle Helidon Allows Unauthenticated HTTP Data Modification

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Tue, 25 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Unauthenticated Access Control Flaw Allows Data Modification
Weaknesses CWE-284

Thu, 20 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Unauthenticated Access Control Flaw Allows Data Modification
Weaknesses CWE-284
CWE-285

Thu, 20 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Helidon Vulnerability: Unauthenticated Remote Data Modification via HTTP
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Helidon Vulnerability: Unauthenticated Remote Data Modification via HTTP
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T17:34:59.448Z

Reserved: 2026-08-13T18:41:45.883Z

Link: CVE-2026-73885

cve-icon Vulnrichment

Updated: 2026-08-25T01:39:27.630Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:20.957

Modified: 2026-08-28T20:19:47.187

Link: CVE-2026-73885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:45:03Z

Weaknesses