Sceawere

Vulnerability Detail

CVE-2026-71165UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-18T21:18:17.820Z",
  "pubdate": "2026-08-18T21:18:17.820Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Imperative Web Server component of Oracle Fusion Middleware Helidon, specifically affecting supported version 3.2.18. This security flaw allows a low-privileged remote attacker with network access via the HTTP protocol to compromise the affected Helidon instance. Successful exploitation of this vulnerability yields unauthorized read, update, insert, and delete access to a subset of data accessible by Helidon, resulting in a direct impact on data confidentiality and integrity without affecting system availability. The vulnerability presents a CVSS 3.1 Base Score of 5.4 with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N, indicating that exploitation requires low privileges, can be executed over the network without user interaction, and maintains a scope unchanged from the vulnerable component. The risk implications include unauthorized data manipulation and information disclosure across enterprise environments deploying the impacted version. Remediation requires applying the appropriate vendor-supplied updates or patches for the Helidon product line.",
  "technicalDetails": "The vulnerability resides within the Imperative Web Server component of the Oracle Fusion Middleware Helidon framework, specifically targeting version 3.2.18. The root cause stems from insufficient access controls or improper authorization enforcement within the request handling pipeline of the HTTP server implementation. Because the flaw is exposed via the network layer, an unconstrained HTTP interface permits remote interaction with vulnerable endpoint handlers.\nTo execute an attack, a low-privileged threat actor must establish network connectivity to the Helidon Imperative Web Server using standard HTTP requests. Due to low complexity and the absence of required user interaction, the attacker crafts malicious HTTP payloads targeting insufficiently protected application endpoints or APIs. Authentication requirements are minimal, necessitating only low privileges within the application context, which allows the attacker to bypass intended authorization boundaries.\nUpon transmission of the crafted HTTP request, the vulnerable Imperative Web Server component processes the input without properly validating whether the authenticated low-privileged user possesses the requisite permissions to perform data modification or retrieval operations. Consequently, the payload behavior facilitates unauthorized data transactions against the underlying data repositories accessible to the Helidon instance.\nThe post-exploitation impact includes unauthorized read access to a subset of sensitive data, as well as unauthorized write capabilities allowing the update, insertion, or deletion of Helidon-accessible data. The attack scope remains unchanged (S:U), restricting the impact primarily to the application data domain rather than escalating to underlying host operating system resources or other discrete server components."
}
CVE-2026-71165: Helidon Imperative Web Server Vulnerability (MEDIUM Severity, CVSS: 5.4) - Sceawere