Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Helidon’s Imperative Web Server affects supported versions 4.0.0 through 4.4.1 and allows an unauthenticated attacker with network access via HTTP to modify or delete data and read a subset of Helidon accessible data. The vulnerability stems from improper access control, which permits unauthorized write or read operations against protected resources and compromises the confidentiality and integrity of data stored or served by the Helidon instance.

Affected Systems

Oracle Corporation's Helidon product, versions 4.0.0 through 4.4.1, is affected. These supported releases are deployed within Oracle Fusion Middleware environments.

Risk and Exploitability

The CVSS v3.1 base score of 6.5 indicates a moderate severity weakness. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not yet listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. However, the attack vector is over the network via HTTP, and the vulnerability is easily exploitable by an unauthenticated user, raising the likelihood that an attacker could successfully conduct unauthorized data operations if the application remains exposed.

Generated by OpenCVE AI on August 29, 2026 at 00:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a patch to Helidon 4.5.0 or upgrade to a newer Helidon release that is not listed as affected
  • Restrict HTTP access to the Helidon service using network segmentation or firewall rules in order to limit exposure to potential attackers
  • Configure proper authentication and authorization controls, ensuring that all privileged operations require validated credentials and that data visibility follows the principle of least privilege

Generated by OpenCVE AI on August 29, 2026 at 00:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Control Failure in Oracle Helidon 4.5.0

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Control Failure in Oracle Helidon 4.5.0

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification and Disclosure in Oracle Helidon 4.5.0
Weaknesses CWE-200
CWE-284

Thu, 20 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification and Disclosure in Oracle Helidon 4.5.0
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Helidon 4.5.0
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Helidon 4.5.0
Weaknesses CWE-200
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T17:56:53.498Z

Reserved: 2026-08-13T18:41:45.884Z

Link: CVE-2026-73893

cve-icon Vulnrichment

Updated: 2026-08-20T18:11:25.524Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:21.870

Modified: 2026-08-28T20:19:48.113

Link: CVE-2026-73893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses