Sceawere

Vulnerability Detail

CVE-2026-71155UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data as well as unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-08-18T21:18:16.617Z",
  "pubdate": "2026-08-18T21:18:16.617Z",
  "executiveSummary": "A security vulnerability has been identified within the Imperative Web Server component of Oracle Fusion Middleware Helidon, specifically affecting version 3.2.18. This remotely exploitable vulnerability poses significant risk due to its ability to cross security boundaries and impact additional products beyond the immediate Helidon deployment, as indicated by the scope change in the CVSS vector. An attacker with low-privileged network access can leverage the HTTP protocol to interact with the vulnerable application, bypassing intended security controls without requiring user interaction.\nSuccessful exploitation of this flaw grants an adversary unauthorized access to critical data or complete access to all data accessible by Helidon, alongside unauthorized capabilities to update, insert, or delete a subset of accessible records. This compromise severely undermines the confidentiality and integrity of the targeted environment. The vulnerability stems from flaws in request handling or access enforcement within the imperative web server architecture, requiring minimal attacker preconditions beyond valid low-privileged credentials and network reachability over HTTP.",
  "technicalDetails": "The vulnerability resides in the Imperative Web Server component of the Helidon product within Oracle Fusion Middleware, specifically impacting version 3.2.18. The root cause involves inadequate validation, improper authorization enforcement, or boundary enforcement failures within the HTTP request processing pipeline of the affected component.\nAttackers initiate exploitation via the network vector using standard HTTP protocols. Because the vulnerability is easily exploitable with low-privileged network access and requires no user interaction, an authenticated user with minimal permissions can craft specific malicious HTTP requests targeted at the Helidon service. The attack flow involves sending these specially crafted payloads to the Imperative Web Server, which fails to properly restrict access or validate the boundaries of the request against the privilege level of the interacting session.\nDue to the scope change (S:C) characteristic of the vulnerability, successful payload execution transcends the immediate administrative domain of Helidon, potentially impacting integrated or downstream products. The post-exploitation impact includes high confidentiality degradation—resulting in unauthorized access to critical data or complete exposure of all Helidon-accessible datasets—and low-to-moderate integrity impact, allowing unauthorized insertion, update, or deletion of specific data objects. The attack requires network accessibility to the Helidon HTTP endpoint and a low-privileged account to authenticate the initial session, successfully circumventing standard access control lists or role-based restrictions implemented within the web server framework."
}
CVE-2026-71155: Helidon Imperative Web Server Vulnerability (HIGH Severity, CVSS: 8.5) - Sceawere