Sceawere

Vulnerability Detail

CVE-2026-73870UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-08-18T21:18:19.220Z",
  "pubdate": "2026-08-18T21:18:19.220Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Imperative Web Server component of the Oracle Fusion Middleware product, specifically affecting Helidon version 4.5.0. This security flaw enables unauthenticated malicious actors with network access via the HTTP protocol to compromise the affected Helidon instance. Successful exploitation of this vulnerability mandates human interaction from an individual other than the attacker, meaning the victim must interact with malicious content or a crafted request.\nThe scope of the vulnerability extends beyond the primary Helidon deployment, potentially impacting additional integrated or ancillary products due to a scope change (S:C). The resulting impact encompasses unauthorized data manipulation capabilities, specifically allowing unauthorized update, insert, or delete access to a subset of data accessible by Helidon, alongside unauthorized read access to confidential data subsets. The vulnerability yields a CVSS 3.1 Base Score of 6.1, driven by moderate impacts to both confidentiality and integrity, while availability remains unaffected.",
  "technicalDetails": "The vulnerability resides in the Imperative Web Server component of Oracle Helidon version 4.5.0. The root cause allows an unauthenticated remote attacker to leverage network accessibility over the HTTP protocol to interact with vulnerable endpoints. Because the attack vector is network-based (AV:N) and attack complexity is low (AC:L), an external threat actor can initiate the exploit stream without possessing prior system privileges (PR:N).\nExploitation mechanics require explicit human interaction (UI:R). Typically, this involves tricking a user or administrator into executing a specific action via HTTP, such as following a maliciously crafted link or accessing a compromised web resource that triggers unexpected behaviors within the Imperative Web Server processing logic. Upon successful initiation, the payload exploits processing deficiencies in the web server component, resulting in a security scope change (S:C) that broadens the attack surface to impact additional products interacting within the same environment.\nPost-exploitation impact is characterized by unauthorized data access and modification vectors. An attacker can achieve unauthorized read access to sensitive subsets of data accessible to Helidon, compromising confidentiality (C:L). Furthermore, the adversary gains unauthorized write capabilities, permitting the insertion, update, or deletion of specific Helidon-accessible data records, thereby compromising data integrity (I:L). The availability of the service remains intact, as no denial-of-service vector is indicated by the base metrics (A:N)."
}
CVE-2026-73870: Oracle Helidon Imperative Web Server Vulnerability (MEDIUM Severity, CVSS: 6.1) - Sceawere