Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Helidon’s Imperative Web Server permits an attacker who can reach the service over HTTP to create, delete, or modify data without authentication. The vulnerability does not affect availability or confidentiality, but it gives full control over any data the server manages, while an attacker does not need prior credentials. The weakness is tied to improper access control mechanisms, allowing a network attacker to write or remove data that should be protected.

Affected Systems

Oracle Corporation Helidon 4.0.0-4.5.0 are affected. No other versions, patches, or products are listed in the CNA data.

Risk and Exploitability

With a CVSS 3.1 base score of 7.5 the flaw presents a high‑severity risk. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based over HTTP and requires no authentication, making exploitation straightforward for any external actor who can reach the Helidon instance. Successful exploitation grants the attacker arbitrary data modification, potentially affecting critical business processes.

Generated by OpenCVE AI on August 28, 2026 at 21:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade Helidon to a version where the flaw is fixed
  • Configure firewall or network segmentation to restrict HTTP access to Helidon so that only trusted hosts or networks can reach it
  • Enable and review audit logging to detect abnormal create, delete, or modify operations on Helidon data

Generated by OpenCVE AI on August 28, 2026 at 21:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Improper Access Control in Oracle Helidon

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Helidon Unauthorized Data Modification via Improper Access Control

Thu, 20 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Helidon Unauthorized Data Modification via Improper Access Control

Wed, 19 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle Helidon 4.5.1

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Modification in Oracle Helidon 4.5.1
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T16:58:36.560Z

Reserved: 2026-08-13T18:41:45.886Z

Link: CVE-2026-73903

cve-icon Vulnrichment

Updated: 2026-08-19T14:24:11.519Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:23.000

Modified: 2026-08-28T20:19:49.743

Link: CVE-2026-73903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T22:00:15Z

Weaknesses