Impact
Oracle Helidon, part of Oracle Fusion Middleware, contains a flaw in its Imperative Web Server component that allows an unauthenticated attacker with network access via HTTP to read a subset of Helidon accessible data. Supported versions 3.0.0 through 3.2.18 are affected. This vulnerability is an information‑exposure flaw that impacts confidentiality and corresponds to CWE‑284, an improper authorization issue.
Affected Systems
Helidon versions 3.0.0 through 3.2.18 are affected. The product is distributed by Oracle Corporation and is referenced in Oracle’s official security advisory for August 2026.
Risk and Exploitability
The CVSS v3.1 score of 5.3 indicates a moderate risk to confidentiality. The EPSS score of less than 1% suggests a low likelihood that the vulnerability is currently being exploited, and the issue is not listed in the CISA KEV catalog. The attack vector is likely a simple HTTP request from an external network; no authentication, privileges, or special user interface are required. Organizations facing this risk can mitigate unauthorized data exposure by applying the official patch or by limiting network exposure.
OpenCVE Enrichment