Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated HTTP access allows unauthorized modification and disclosure of Helidon data
Action: Apply Patch
AI Analysis

Impact

The LRA component of Oracle Helidon is vulnerable to a credential‑less authorization bypass (CWE‑284) that permits an unauthenticated attacker to modify, insert, or delete data via HTTP endpoints. Because no credentials are required, the attacker can target exposed endpoints and achieve the specified impacts. The flaw has a CVSS v3.1 base score of 6.5.

Affected Systems

Oracle Helidon versions 4.0.0-4.5.4, and the vulnerability applies to any deployment that has LRA enabled and publicly reachable over the network.

Risk and Exploitability

The EPSS score of less than 1 % indicates a low expected exploitation vulnerability remains fully exploitable without authentication over a common network protocol. The flaw is not listed in CISA’s KEV catalog. Attackers can trigger the issue by sending crafted HTTP requests to the Helidon endpoint from any host with network connectivity, making the risk significant for publicly exposed instances. Given the CVSS score and the lack of mitigating controls in affected versions, applying the vendor’s patch should be prioritized.

Generated by OpenCVE AI on September 21, 2026 at 02:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available Oracle Helidon patch that addresses the vulnerability.
  • Restrict network access to Helidon endpoints by implementing firewall rules or network segmentation to block unauthorized HTTP traffic.
  • If the LRA component is not required, disable or remove it from the Helidon deployment.

Generated by OpenCVE AI on September 21, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Authorization Bypass in Oracle Helidon LRA

Mon, 21 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification and Disclosure in Helidon
Weaknesses CWE-284
CWE-862

Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification and Disclosure in Helidon
Weaknesses CWE-284
CWE-862

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T00:03:16.904Z

Reserved: 2026-08-31T15:40:57.360Z

Link: CVE-2026-83460

cve-icon Vulnrichment

Updated: 2026-09-20T23:54:56.651Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:54.813

Modified: 2026-09-25T19:26:27.410

Link: CVE-2026-83460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:15:08Z

Weaknesses