Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-09-15
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access and Modification
Action: Patch Immediately
AI Analysis

Impact

Vulnerability in Oracle Helidon's helidon-dbclient-mongodb component allows an unauthenticated attacker with network access via HTTP to obtain unauthorized read access to critical data, as well as write access that could insert, update, or delete Helidon-accessible data. The flaw also permits an attacker to trigger a partial denial of service. The base CVSS score of 7.0 reflects significant confidentiality and integrity impact. The vulnerability is difficult to exploit but exists in the public exposure of Helidon applications.

Affected Systems

Oracle Helidon versions 3.0.0 through 3.2.20 and 4.0.0 through 4.5.4 are affected. The vulnerability resides in the helidon-dbclient-mongodb component, which interfaces with MongoDB databases over HTTP. Any Oracle Helidon deployment that exposes this component without authentication is susceptible.

Risk and Exploitability

With a CVSS 3.1 Base Score of 7.0, the risk is considered high. The EPSS score indicates a very low probability of exploitation, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, suggesting no confirmed exploits but a potential for future attacks. The likely attack vector is raw HTTP traffic to the Helidon service, and an attacker would need network connectivity to the exposed endpoint. Because the vulnerability requires no credentials, it is considered a high-impact unauthenticated attack.

Generated by OpenCVE AI on September 18, 2026 at 19:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle security update referenced in the official Oracle security alert to patch Helidon.
  • Restrict network access to Helidon HTTP endpoints using firewall rules or network segmentation, ensuring only trusted networks or internal addresses can reach the service.
  • Enable or enforce authentication and authorization on Helidon routes that interact with MongoDB, ensuring that only properly authenticated users can perform read or write operations.

Generated by OpenCVE AI on September 18, 2026 at 19:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Abuse Enables Unauthorized Data Access and Manipulation in Oracle Helidon

Thu, 17 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Abuse Enables Unauthorized Data Access and Manipulation in Oracle Helidon
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:13:09.426Z

Reserved: 2026-08-31T15:40:57.348Z

Link: CVE-2026-83231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:34.960

Modified: 2026-09-17T16:18:10.900

Link: CVE-2026-83231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T19:45:13Z

Weaknesses