Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-08-18
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker who can reach Oracle Helidon over HTTP can perform unauthorized updates, inserts, or deletions of protected data, read a subset of information that should not be exposed, and trigger a partial denial of service. Supported Helidon versions 4.0.0 through 4.4.1 are affected. The vulnerability has a CVSS 3.1 Base Score of 7.3, indicating moderate impacts on confidentiality, integrity, and availability, and stems from a lack of proper access control enforcement (CWE‑284).

Affected Systems

Oracle Helidon versions 4.0.0 through 4.4.1 are affected. No other products are identified in the supplied data.

Risk and Exploitability

The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L) shows that the attacker needs only network connectivity and no credentials or user interaction to succeed. The EPSS score of < 1% indicates a very low exploitation probability, yet the lack of an authentication requirement suggests that compromising Helidon can still be achievable in environments that expose it to external traffic. The vulnerability is not currently listed in CISA’s KEV catalog, meaning no widespread exploitation has been reported. Nonetheless, the potential for data loss, unauthorized manipulation, and service interruption warrants prompt remediation.

Generated by OpenCVE AI on August 28, 2026 at 21:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult Oracle’s security alert for corrective actions and apply any vendor‑issued patch or upgrade as soon as it becomes available.
  • Limit external HTTP exposure to the Helidon service by configuring firewall rules, VPN access, or other network segmentation techniques so that only trusted hosts may reach the server.
  • Enable comprehensive logging and audit trails for Helidon’s request handling, and monitor these logs for anomalous or unauthorized activity.
  • If application‑level authentication or stricter session management is available, enable it to add an additional barrier against unauthenticated exploitation.

Generated by OpenCVE AI on August 28, 2026 at 21:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification and Partial Denial of Service in Oracle Helidon

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploitation of Oracle Helidon 4.5.0

Thu, 20 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploitation of Oracle Helidon 4.5.0

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification and Partial Denial of Service in Oracle Helidon 4.5.0
Weaknesses CWE-287

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Data Modification and Partial Denial of Service in Oracle Helidon 4.5.0
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T17:31:44.687Z

Reserved: 2026-08-13T18:41:45.889Z

Link: CVE-2026-73918

cve-icon Vulnrichment

Updated: 2026-08-19T12:08:08.397Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:24.743

Modified: 2026-08-28T20:19:51.010

Link: CVE-2026-73918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:45:03Z

Weaknesses