Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-08-18
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component, contains a severe flaw that permits an unauthenticated attacker who can reach the service via HTTP to compromise the system. The vulnerability enables the attacker to create, delete, or modify resources, thereby exposing critical data and allowing unauthorized modification of application state. Additionally, the flaw can be used to cause partial denial of service. This is a type of Access Control weakness (CWE-284). The impact includes confidentiality, integrity, and availability, as reflected in the CVSS vector.

Affected Systems

Affected systems are limited to Oracle Helidon deployments with versions 4.0.0 through 4.4.1, as these are the only releases identified as vulnerable.

Risk and Exploitability

Risk and exploitability are high: the CVSS v3.1 score of 9.4 reflects a low attack complexity, no privileges, no user interaction, and an unmodified scope, indicating the flaw can be exploited by any networked attacker. The EPSS score of < 1% suggests a very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog; the description explicitly characterizes it as easily exploitable via standard HTTP access, reinforcing the need for immediate attention.

Generated by OpenCVE AI on August 28, 2026 at 20:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle's official security releases for Helidon and apply any patch addressing CVE-2026-73920.
  • Restrict HTTP access to Helidon by applying firewall rules or IP whitelisting, ensuring only trusted networks can reach the service.
  • Enable logging and monitoring of Helidon access patterns to detect anomalous requests that may indicate exploitation attempts.

Generated by OpenCVE AI on August 28, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Exploit in Oracle Helidon Web Server

Fri, 28 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Helidon 4.5.0 Vulnerability: Unauthenticated HTTP Access Enables Unauthorized Data Modification and Partial Denial of Service

Thu, 20 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Helidon 4.5.0 Vulnerability: Unauthenticated HTTP Access Enables Unauthorized Data Modification and Partial Denial of Service

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title Remote Exploitation via Unauthenticated HTTP Access in Oracle Helidon 4.5.0
Weaknesses CWE-287

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Remote Exploitation via Unauthenticated HTTP Access in Oracle Helidon 4.5.0
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:4.5.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T04:04:27.200Z

Reserved: 2026-08-13T18:41:45.889Z

Link: CVE-2026-73920

cve-icon Vulnrichment

Updated: 2026-08-19T12:08:05.417Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:24.967

Modified: 2026-08-28T05:16:45.130

Link: CVE-2026-73920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:30:08Z

Weaknesses