Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-09-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification and Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Helidon MicroProfile Security allows a low‑privileged attacker with network access via HTTP to perform unauthorized updates, inserts, or deletes on data exposed by Helidon, and to read a subset of that data. The flaw arises from improper authorization controls in the Helidon MicroProfile Security component, leading to confidentiality and integrity impacts as reflected in the CVSS vector. Availability remains unaffected.

Affected Systems

Oracle Helidon versions 4.0.0 through 4.5.4 are affected. These are part of Oracle Fusion Middleware and are deployed in environments that expose HTTP endpoints for Helidon services.

Risk and Exploitability

The CVSS base score of 5.4 (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) indicates moderate risk. The EPSS score of less than 1% signals a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers only need network connectivity to a Helidon HTTP interface; no local privilege or user interaction is required beyond a low privileged user context. The exploit is considered easily exploitable based on vendor characterization.

Generated by OpenCVE AI on September 21, 2026 at 23:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Helidon patch or upgrade to a supported version that includes the security fix.
  • Restrict Helidon’s HTTP endpoints to trusted networks or internal hosts to prevent public exposure.
  • Re‑configure Helidon deployments to enforce proper authentication and authorization rules, ensuring that only authorized users can perform write or read operations on protected data.

Generated by OpenCVE AI on September 21, 2026 at 23:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Helidon MicroProfile Security Authorization Flaw Enables Unauthorized Data Access

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Helidon MicroProfile Security Authorization Flaw Enables Unauthorized Data Access

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Helidon MicroProfile Security
Weaknesses CWE-284
CWE-285

Wed, 16 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Helidon MicroProfile Security
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle helidon
CPEs cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle helidon
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:04:50.739Z

Reserved: 2026-08-31T15:40:57.362Z

Link: CVE-2026-83488

cve-icon Vulnrichment

Updated: 2026-09-21T19:04:47.214Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:18:56.593

Modified: 2026-09-25T19:34:35.090

Link: CVE-2026-83488

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T23:15:13Z

Weaknesses