Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Helidon, part of Oracle Fusion Middleware, contains a vulnerability in its Imperative Web Server component. The flaw exists in Helidon versions 4.0.0 through 4.4.1 and can be exploited by an unauthenticated attacker with network connectivity to the server via standard HTTP traffic. The vulnerability allows the attacker to bypass authentication entirely, enabling arbitrary code execution and full takeover of the Helidon environment. This is a CWE-284 Authorization vulnerability.

Affected Systems

Oracle Helidon product, specifically versions 4.0.0 through 4.4.1, is affected. The component involved is the Imperative Web Server.

Risk and Exploitability

Given the CVSS score of 9.8 and the lack of a required user interaction, the risk level is high. The EPSS score is < 1%, indicating a very low probability of exploitation in the general population, but the vulnerability's vector demonstrates that any machine with network access to Helidon can exercise the exploit. The vulnerability is not yet listed in CISA’s KEV catalog, indicating no publicly known exploits at the time of this analysis. However, it remains a significant threat due to its ease of exploitation and the complete control it grants to attackers.

Generated by OpenCVE AI on August 28, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-provided patch or upgrade to a newer Helidon release that addresses the remote code execution flaw.
  • Restrict network exposure by configuring firewall rules or a reverse proxy to limit HTTP access to trusted hosts only.
  • Verify that authentication and authorization mechanisms are correctly implemented so that only authenticated users with appropriate privileges can access Helidon resources, addressing the underlying CWE‑284 weakness.
  • Monitor Helidon logs and network traffic for signs of exploitation attempts.

Generated by OpenCVE AI on August 28, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Remote Code Execution Vulnerability

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Unrestricted Remote Code Execution Vulnerability in Oracle Helidon 4.5.0

Thu, 20 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unrestricted Remote Code Execution Vulnerability in Oracle Helidon 4.5.0
Weaknesses CWE-287

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Wed, 19 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Helidon Imperative Web Server
Weaknesses CWE-287

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Helidon Imperative Web Server
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-27T21:37:12.858Z

Reserved: 2026-08-13T18:41:45.886Z

Link: CVE-2026-73905

cve-icon Vulnrichment

Updated: 2026-08-19T14:27:24.069Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:23.227

Modified: 2026-08-28T00:18:11.690

Link: CVE-2026-73905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:30:05Z

Weaknesses