Impact
A vulnerability exists in the Imperative Web Server component of Oracle Helidon, affecting versions 1.0.0 through 1.4.18. The flaw allows an unauthenticated attacker with HTTP network access to bypass authentication and create, delete, or modify critical data. The attacker can also gain full access to all Helidon‑accessible data, compromising both confidentiality and integrity. This issue is classified as CWE‑284 (Improper Access Control) and has a CVSS v3.1 base score of 9.1, highlighting the severe impact on confidentiality and integrity.
Affected Systems
Oracle Helidon versions 1.0.0 through 1.4.18 are affected, regardless of patch level, and vulnerabilities are present in the Imperative Web Server component.
Risk and Exploitability
The high CVSS score signals critical risk. Exploitability is straightforward: any remote user with HTTP connectivity to the Helidon instance can trigger the exploit, thanks to the lack of authentication and the network‑level attack vector. EPSS score is <1%, indicating a very low probability of exploitation, while the issue is not listed in the CISA KEV catalogue, but the network reach and severity underline the importance of timely mitigation.
OpenCVE Enrichment