Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-08-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Helidon Imperative Web Server component of Oracle Fusion Middleware allows a low‑privileged attacker with network access via HTTP to perform unauthorized update, insert, delete, or read operations on data exposed by the application. The flaw is a result of missing or weak access control. Successful exploitation can lead to both confidentiality and integrity impacts, as reflected in the CVSS score of 5.4.

Affected Systems

The vulnerability affects Oracle Helidon versions from 3.0.0 through 3.2.17. No other products or versions are listed as impacted by the advisory.

Risk and Exploitability

The CVSS v3.1 base score of 5.4 indicates moderate risk to confidentiality and integrity. Because the flaw can be triggered remotely over untrusted networks without user interaction, the EPSS score is below 1%, indicating a very low but non‑zero likelihood of exploitation. The flaw is not identified as a Known Exploited Vulnerability by CISA, but organizations running Oracle Helidon versions 3.0.0 through 3.2.17 should assess the exposure and consider immediate mitigation.

Generated by OpenCVE AI on August 28, 2026 at 21:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Helidon 3.2.18 patch or upgrade to a supported version according to the vendor’s security advisory.
  • Limit HTTP traffic to the Helidon service by configuring firewall rules or network segmentation to allow traffic only from trusted IP addresses.
  • Review and enforce proper access controls within Helidon to ensure that only authorized users can perform update, insert, or delete actions on exposed data.

Generated by OpenCVE AI on August 28, 2026 at 21:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privileged HTTP Access in Oracle Helidon 3.2.18

Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low‑Privileged HTTP Access in Oracle Helidon 3.2.18

Thu, 20 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Data Access Control Vulnerability

Wed, 19 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Data Access Control Vulnerability

Wed, 19 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Unauthorized Data Modification and Disclosure Vulnerability
Weaknesses CWE-285
CWE-862

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Unauthorized Data Modification and Disclosure Vulnerability
Weaknesses CWE-285
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:3.2.18:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T18:13:34.785Z

Reserved: 2026-08-13T18:41:45.889Z

Link: CVE-2026-73919

cve-icon Vulnrichment

Updated: 2026-08-19T14:01:31.479Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:24.853

Modified: 2026-08-28T20:19:51.130

Link: CVE-2026-73919

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T21:45:03Z

Weaknesses