Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-08-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Imperative Web Server component of Oracle Helidon versions 4.0.0 through 4.4.1. An unauthenticated attacker with network access over HTTP may exploit a missing authorization check, allowing unauthorized update, insert, or delete operations on Helidon‑accessible data and read access to a subset of that data. Successful exploitation requires human interaction from a person other than the attacker, and the flaw can potentially impact other products due to a scope change, though it does not provide remote code execution. The resulting confidentiality and integrity impacts are reflected in the CVSS base score of 6.1.

Affected Systems

This issue affects Oracle Helidon versions 4.0.0 through 4.4.1, a component of Oracle Fusion Middleware. The product is deployed as the imperative web server and is listed in the referenced Oracle security alert. No other product versions are listed as affected.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity vulnerability. The EPSS score is <1% and the vulnerability has not been included in the CISA KEV catalog, implying no widespread exploitation to date. The description states that the vulnerability is easily exploitable via HTTP by an unauthenticated attacker, yet successful attacks require human interaction from a person other than the attacker, which reduces the practical exploitation likelihood. Although the scope change could allow impact on additional components, there is no evidence of remote code execution. Overall, the risk is higher than low‑severity patches but lower than critical issues; mitigation is advisable promptly.

Generated by OpenCVE AI on August 28, 2026 at 21:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Helidon to a patched version that includes the authorization fix
  • Restrict HTTP exposure of Helidon by applying firewall or reverse‑proxy rules and enforce authentication where possible
  • Review and harden Helidon’s access controls to ensure proper authorization checks for all data operations

Generated by OpenCVE AI on August 28, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Helidon Authorization Bypass Allows Unauthenticated Data Modification via HTTP

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Fri, 21 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authorization Bypass Enables Data Modification and Disclosure in Oracle Helidon 4.5.0

Thu, 20 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authorization Bypass Enables Data Modification and Disclosure in Oracle Helidon 4.5.0

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Oracle Helidon 4.5.0 Improper Access Control Enables Unauthorized Data Access
Weaknesses CWE-284

Thu, 20 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Oracle Helidon 4.5.0 Improper Access Control Enables Unauthorized Data Access
Weaknesses CWE-284

Wed, 19 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploit in Oracle Helidon 4.5.0 Leading to Unauthorized Data Modification
Weaknesses CWE-284

Wed, 19 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Network Exploit in Oracle Helidon 4.5.0 Leading to Unauthorized Data Modification
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:02:59.953Z

Reserved: 2026-08-13T18:41:45.885Z

Link: CVE-2026-73898

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:49.454Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:22.440

Modified: 2026-08-28T20:19:49.163

Link: CVE-2026-73898

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T22:00:15Z

Weaknesses