Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and access
Action: Immediate Patch
AI Analysis

Impact

Helidon includes an authorization bypass that permits a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data, effectively granting full access to all data managed by the instance. This is an improper authorization weakness (CWE‑284) that can compromise both confidentiality and integrity of Helidon data. The vulnerability allows non‑admin users to perform privileged operations that they should not have the right to execute, thereby sustaining an elevated foothold in the application.

Affected Systems

Affected systems are Oracle Helidon versions 3.0.0 through 3.2.20 and 4.0.0 through 4.5.4, as stated in the vendor advisory and CNA information.

Risk and Exploitability

The CVSS base score of 8.1 indicates significant risk, requiring only normal network access and low privilege. EPSS is under 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited yet. The likely attack vector is over HTTP, where a low‑privileged actor can send crafted requests to the helidon‑security‑providers‑idcs‑mapper component to bypass authorization checks and modify data.

Generated by OpenCVE AI on September 18, 2026 at 18:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Helidon to a supported secure version (>= 3.2.21 or >= 4.5.5).
  • Restrict HTTP access to Helidon services to trusted networks or implement firewall ACLs.
  • Disable the helidon‑security‑providers‑idcs‑mapper component if it is not required, or reconfigure it to enforce proper authorization checks.

Generated by OpenCVE AI on September 18, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Enabling Unauthorized Data Modification in Oracle Helidon

Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass Enabling Unauthorized Data Modification in Oracle Helidon
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:47.064Z

Reserved: 2026-08-31T15:40:57.359Z

Link: CVE-2026-83439

cve-icon Vulnrichment

Updated: 2026-09-18T18:15:18.442Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:52.520

Modified: 2026-09-28T15:20:32.003

Link: CVE-2026-83439

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:15:06Z

Weaknesses