Sceawere

Vulnerability Detail

CVE-2026-73865UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-18T21:18:18.650Z",
  "pubdate": "2026-08-18T21:18:18.650Z",
  "executiveSummary": "An unauthenticated, remotely exploitable vulnerability affects the Imperative Web Server component of Oracle Fusion Middleware Helidon version 3.2.18. This flaw allows malicious actors with network access via the HTTP protocol to interact with the vulnerable application and compromise its security posture without requiring prior authentication or user interaction. Successful exploitation of this security defect grants unauthorized adversaries extensive capabilities, specifically resulting in unauthorized creation, deletion, or modification access to critical data, alongside unauthorized read access to sensitive or complete Helidon accessible data. The CVSS 3.1 base score is recorded at 9.1, highlighting severe confidentiality and integrity impacts. The attack complexity is low, making it easily exploitable for threat actors targeting exposed endpoints. Consequently, the risk implications are critical, posing severe threats to organizational data integrity and information confidentiality across affected Helidon deployments.",
  "technicalDetails": "The identified vulnerability resides within the Imperative Web Server component of the Helidon product, specifically impacting version 3.2.18. The root cause stems from insufficient access controls or improper handling of incoming HTTP requests processed by the web server layer, which permits unauthorized execution paths and data manipulation. The vulnerability features a network attack vector (AV:N), meaning that exploitation does not require local access to the host operating system and can be executed remotely across a network boundary via standard HTTP communications. The attack complexity is evaluated as low (AC:L), indicating that the targeted service lacks robust defensive mechanisms or state validation logic to impede exploitation attempts. Furthermore, the vulnerability requires zero privileges (PR:N) and zero user interaction (UI:N), allowing any unauthenticated remote attacker to interact directly with the vulnerable HTTP endpoints.\nThe step-by-step attack flow begins with the attacker establishing network connectivity to the exposed Helidon Imperative Web Server instance over HTTP. Because authentication and privilege requirements are entirely absent, the attacker can immediately dispatch crafted HTTP requests designed to target the vulnerable functional component. Upon receipt, the vulnerable server processes the malicious payload without adequately validating the sender's authorization status or the semantic validity of the requested operation. This flaw bypasses intended security boundaries, allowing the payload to execute unauthorized data-handling routines.\nThe post-exploitation impact includes severe breaches of confidentiality and integrity (C:H/I:H/A:N). The attacker gains the ability to compromise critical data assets stored or managed by Helidon through unauthorized read actions, exposing sensitive information. Concurrently, the adversary can perform unauthorized create, delete, and modify actions against critical or complete Helidon accessible data, leading to severe data corruption, unauthorized data tampering, or complete loss of data integrity. The availability vector remains unaffected (A:N), as the primary impact focuses on data confidentiality and integrity rather than denial of service."
}
CVE-2026-73865: Helidon Imperative Web Server Vulnerability (CRITICAL Severity, CVSS: 9.1) - Sceawere