Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Imperative Web Server component of Oracle Helidon, affecting versions 1.0.0 through 1.4.18. The flaw allows an unauthenticated attacker with HTTP network access to bypass authentication and create, delete, or modify critical data. The attacker can also gain full access to all Helidon‑accessible data, compromising both confidentiality and integrity. This issue is classified as CWE‑284 (Improper Access Control) and has a CVSS v3.1 base score of 9.1, highlighting the severe impact on confidentiality and integrity.

Affected Systems

Oracle Helidon versions 1.0.0 through 1.4.18 are affected, regardless of patch level, and vulnerabilities are present in the Imperative Web Server component.

Risk and Exploitability

The high CVSS score signals critical risk. Exploitability is straightforward: any remote user with HTTP connectivity to the Helidon instance can trigger the exploit, thanks to the lack of authentication and the network‑level attack vector. EPSS score is <1%, indicating a very low probability of exploitation, while the issue is not listed in the CISA KEV catalogue, but the network reach and severity underline the importance of timely mitigation.

Generated by OpenCVE AI on August 28, 2026 at 19:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security alert at the provided link and apply the latest Helidon release that addresses CVE-2026-73924.
  • If an update cannot be applied immediately, restrict external HTTP access to the Helidon service by firewall rules or a VPN to only trusted IP ranges.
  • Enforce proper authentication and authorization on all HTTP endpoints to prevent unauthorized create, delete, and modify operations.
  • Enable comprehensive logging of Helidon activity and monitor for anomalous requests.

Generated by OpenCVE AI on August 28, 2026 at 19:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthorized HTTP Access and Data Modification in Oracle Helidon

Fri, 28 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*

Thu, 20 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Unauthenticated HTTP Access Control Flaw

Thu, 20 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Helidon Imperative Web Server Unauthenticated HTTP Access Control Flaw

Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access and Data Modification in Oracle Helidon 1.4.19
Weaknesses CWE-862

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access and Data Modification in Oracle Helidon 1.4.19
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:1.4.19:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-28T04:19:35.748Z

Reserved: 2026-08-13T18:41:45.890Z

Link: CVE-2026-73924

cve-icon Vulnrichment

Updated: 2026-08-19T14:04:13.264Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T21:18:25.430

Modified: 2026-08-28T05:16:45.373

Link: CVE-2026-73924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:45:03Z

Weaknesses