Sceawere

Vulnerability Detail

CVE-2026-71157UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-18T21:18:16.840Z",
  "pubdate": "2026-08-18T21:18:16.840Z",
  "executiveSummary": "An unauthenticated information disclosure vulnerability has been identified in the Helidon product of Oracle Fusion Middleware, specifically within the Imperative Web Server component. This security flaw allows remote attackers with network access via HTTP to bypass authorization boundaries and gain unauthorized read access to a specific subset of data accessible by the application.\nThe vulnerability is classified under CVSS 3.1 with a base score of 5.3, impacting confidentiality exclusively, with no direct integrity or availability impacts reported. Exploitation of this vulnerability requires no privileges and no user interaction, making it easily exploitable over the network.\nThe affected supported version is strictly limited to Helidon 4.5.0. Successful exploitation poses a risk to data confidentiality by exposing sensitive operational or application data to unauthorized external entities.\nOrganizations utilizing the affected version should implement defensive measures and apply vendor-supplied patches or upgrades as soon as they become available to neutralize the threat vectors associated with the Imperative Web Server component.",
  "technicalDetails": "The vulnerability resides within the Imperative Web Server component of Oracle Fusion Middleware Helidon version 4.5.0. The root cause stems from improper access control enforcement or mishandling of HTTP requests, which allows unauthenticated remote clients to query or retrieve sensitive data structures that should otherwise be restricted.\nFrom an attack vector perspective, the vulnerability is exposed via the network (AV:N). The attack complexity is rated as low (AC:L), indicating that no specialized race conditions, memory corruption techniques, or complex pre-conditions are required to successfully execute the exploit. Furthermore, the vulnerability requires zero privileges (PR:N) and no user interaction (UI:N), enabling automated scanners or malicious actors to target the service directly.\nThe attack flow proceeds as follows: an unauthenticated attacker crafts a specific HTTP request directed at the vulnerable Helidon Imperative Web Server endpoint. Due to the flaw in request processing or access validation within the component, the server fails to properly authenticate or authorize the incoming request against the requested data resource. Consequently, the server processes the payload and returns a response containing restricted application data.\nThe post-exploitation impact is limited to unauthorized read access (C:L, I:N, A:N), meaning the attacker cannot modify data, execute arbitrary code, or cause a denial of service through this specific vector. However, the retrieved data subset may contain sensitive configuration details, internal identifiers, or user-accessible information that could facilitate subsequent attacks against the broader infrastructure."
}
CVE-2026-71157: Helidon Imperative Web Server Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere