Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Helidon 4.0.0‑4.4.1 in Oracle Fusion Middleware contains an authorization flaw in the Imperative Web Server component that allows an unauthenticated attacker with network access over HTTP to read a subset of data exposed by the application. The exploit does not require credentials, and success results in unauthorized read access to Helidon data. This vulnerability is classified as CWE‑284 and carries a moderate CVSS v3.1 base score of 5.3, indicating a confidentiality impact.

Affected Systems

Oracle Helidon versions 4.0.0 through 4.4.1 are affected. The flaw resides in the Helidon Imperative Web Server component, which is part of Oracle Fusion Middleware. No later Helidon releases have been identified as vulnerable; the advisory does not mention versions beyond 4.4.1.

Risk and Exploitability

The CVSS v3.1 base score of 5.3 denotes a moderate severity that primarily affects confidentiality. The EPSS score of less than 1 % indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known exploitation at present. An attacker can reach the affected service via HTTP without authentication, exploiting the missing authorization checks to retrieve a subset of Helidon data. This network‑based attack can occur in any environment where Helidon is exposed to the Internet or an internal network.

Generated by OpenCVE AI on August 28, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply available Oracle patch or upgrade to a non‑vulnerable Helidon release
  • Restrict HTTP access to Helidon to trusted networks or implement firewall rules to limit exposure
  • Monitor application and network logs for unauthorized data read attempts

Generated by OpenCVE AI on August 28, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Helidon Unauthorized Data Access Vulnerability

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Exposure via Oracle Helidon Web Server

Fri, 21 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Exposure via Oracle Helidon Web Server
Weaknesses CWE-200

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Data Exposure in Oracle Helidon 4.5.0

Thu, 20 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Data Exposure in Oracle Helidon 4.5.0
Weaknesses CWE-200

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access to Helidon Data via Unauthenticated HTTP
Weaknesses CWE-200

Wed, 19 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access to Helidon Data via Unauthenticated HTTP
Weaknesses CWE-200

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:26:56.349Z

Reserved: 2026-08-13T18:41:45.883Z

Link: CVE-2026-73889

cve-icon Vulnrichment

Updated: 2026-08-20T18:11:19.435Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:21.407

Modified: 2026-08-28T20:19:47.637

Link: CVE-2026-73889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:45:03Z

Weaknesses