Sceawere

Vulnerability Detail

CVE-2026-73867UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:18:18.873Z",
  "pubdate": "2026-08-18T21:18:18.873Z",
  "executiveSummary": "An easily exploitable security vulnerability has been identified in the Imperative Web Server component of Oracle Fusion Middleware Helidon, specifically affecting version 3.2.18.\nThe vulnerability allows an unauthenticated remote attacker with network access via the HTTP protocol to compromise the targeted Helidon instance.\nSuccessful exploitation of this flaw can result in unauthorized read access to a subset of Helidon-accessible data, as well as unauthorized update, insert, or delete access to certain data resources.\nThe vulnerability is assigned a CVSS 3.1 Base Score of 6.5, with impacts strictly limited to confidentiality and integrity without affecting system availability.\nThe attack vector is network-based requiring low complexity, with no user interaction or prior privileges necessary, making network reachability the primary prerequisite for successful exploitation.",
  "technicalDetails": "The vulnerability resides within the Imperative Web Server component of the Oracle Fusion Middleware Helidon framework, specifically impacting version 3.2.18.\nThe security flaw stems from insufficient input validation or improper access controls handled by the Imperative Web Server when processing incoming HTTP requests.\nAn unauthenticated attacker positioned on the network can exploit this vulnerability by crafting and transmitting malicious HTTP requests directly to the exposed Helidon service endpoints.\nBecause the attack requires no authentication (PR:N) and no user interaction (UI:N), an external threat actor can initiate the attack sequence immediately upon establishing network connectivity (AV:N) with the target.\nThe attack complexity is classified as low (AC:L), indicating that the conditions or configurations required to execute the exploit reliably are minimal.\nDuring the attack flow, the malicious HTTP payload bypasses intended authorization boundaries enforced by the web server framework.\nUpon successful payload processing by the vulnerable component, the application executes unauthorized data operations.\nThe post-exploitation impact includes the exposure of sensitive information through unauthorized read access to a subset of accessible data, and the compromise of data integrity through unauthorized insertion, update, or deletion operations.\nThe scope remains unchanged (S:U), meaning the vulnerability is strictly contained within the affected Helidon component and does not directly escalate to underlying system layers or other distinct security scopes."
}
CVE-2026-73867: Helidon Imperative Web Server Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere