Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Helidon 4.0.0-4.4.1 has an improper access control flaw in its Imperative Web Server component that allows an attacker with low privilege and network access over HTTP to perform unauthorized update, insert, delete, and read operations on data that the attacker should not be able to see or modify. The vulnerability, identified as CWE-284, results in confidentiality and integrity impacts, reflected in a CVSS 3.1 base score of 5.4.

Affected Systems

The flaw affects Helidon versions 4.0.0 through 4.4.1; no other releases or Oracle products are listed as impacted.

Risk and Exploitability

With a CVSS score of 5.4 the risk is moderate, and the EPSS score of < 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. Attackers can exploit the flaw over HTTP using a low‑privileged client, leveraging insufficient authorization checks to gain unauthorized data access.

Generated by OpenCVE AI on August 29, 2026 at 00:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle Helidon 4.5.0 patch or upgrade to a newer, unaffected Helidon release as detailed in the Oracle Security Alert CSPU Aug 2026.
  • Restrict direct HTTP exposure of the Helidon service by configuring firewalls or ACLs to allow traffic only from trusted IP addresses or internal networks.
  • Enforce strong authentication and proper authorization controls within Helidon to ensure that only users with the appropriate permissions can perform insert, update, delete, or read operations.

Generated by OpenCVE AI on August 29, 2026 at 00:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Helidon Improper Access Control Allows Unauthorized Data Operations via HTTP

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Helidon 4.5.0 Enables Unauthorized Data Modification and Retrieval

Thu, 20 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Helidon 4.5.0 Enables Unauthorized Data Modification and Retrieval

Wed, 19 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Attack Enables Unauthorized Data Access in Oracle Helidon 4.5.0
Weaknesses CWE-862

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Attack Enables Unauthorized Data Access in Oracle Helidon 4.5.0
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:12:13.100Z

Reserved: 2026-08-13T18:41:45.887Z

Link: CVE-2026-73911

cve-icon Vulnrichment

Updated: 2026-08-19T14:01:36.696Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:23.907

Modified: 2026-08-28T20:19:50.557

Link: CVE-2026-73911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:15:06Z

Weaknesses