Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Helidon product suffers from an unauthenticated HTTP vulnerability that stems from improper authentication and access control weakness (CWE-284). Affected versions are 1.0.0 through 1.4.19. An attacker can exploit this flaw to execute arbitrary code on the server, compromising confidentiality, integrity, and availability of the Helidon instance and potentially gaining full system control.

Affected Systems

Oracle Helidon versions 1.0.0 through 1.4.19 are affected. Users running any of these releases may be compromised without additional security controls.

Risk and Exploitability

The vulnerability is easily exploitable over the network, requiring only an unauthenticated HTTP connection. The CVSS score of 9.8 indicates a high risk, and the EPSS score is < 1%, indicating a very low but non‑zero exploitation probability. The lack of KEV listing does not reduce the need for prompt action.

Generated by OpenCVE AI on August 28, 2026 at 19:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch or upgrade to a later Helidon version that contains the security fix
  • Restrict external HTTP access to the Helidon server using firewall rules or network segmentation, allowing only trusted hosts to connect
  • Enable detailed audit logging for the Helidon server and monitor logs for suspicious or repeated unauthenticated HTTP requests

Generated by OpenCVE AI on August 28, 2026 at 19:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution Vulnerability in Oracle Helidon

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Helidon 1.4.20

Thu, 20 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Helidon 1.4.20

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Remote Code Execution via Unauthenticated HTTP Access (Version 1.4.20)
Weaknesses CWE-287

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Helidon Web Server Remote Code Execution via Unauthenticated HTTP Access (Version 1.4.20)
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:1.4.20:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-27T21:39:26.690Z

Reserved: 2026-08-13T18:41:45.889Z

Link: CVE-2026-73921

cve-icon Vulnrichment

Updated: 2026-08-19T14:04:17.904Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:25.087

Modified: 2026-08-28T00:18:11.920

Link: CVE-2026-73921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:00:16Z

Weaknesses