Sceawere

Vulnerability Detail

CVE-2026-73871UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-18T21:18:19.333Z",
  "pubdate": "2026-08-18T21:18:19.333Z",
  "executiveSummary": "A vulnerability has been identified within the Helidon product of Oracle Fusion Middleware, specifically affecting the Imperative Web Server component in version 3.2.18. This security flaw enables an unauthenticated remote attacker with network access via the HTTP protocol to compromise the confidentiality of the target system, resulting in unauthorized read access to a subset of Helidon accessible data.\nThe vulnerability is characterized by its low complexity and ease of exploitation, requiring no user interaction, privileges, or prior authentication. Because the attack vector is network-based and openly accessible over HTTP, attackers can execute requests to retrieve sensitive data directly from the vulnerable service. The primary impact is strictly confined to confidentiality, leaving integrity and availability unaffected.\nFrom a risk management perspective, this exposure introduces potential data leakage vectors that could expose internal application states, configuration details, or sensitive business logic handled by the Imperative Web Server. Organizations utilizing the affected version must evaluate their exposure surface and implement applicable remediation strategies to prevent unauthorized information disclosure.",
  "technicalDetails": "The vulnerability resides in the Imperative Web Server component of Oracle Fusion Middleware Helidon version 3.2.18. The architectural root cause involves insufficient validation or improper access controls applied to HTTP request handling, which permits unauthorized retrieval of restricted data subsets.\nExploitation is conducted entirely over the network utilizing standard HTTP communication channels. Since the vulnerability requires zero privileges (PR:N) and no user interaction (UI:N), an unauthenticated threat actor can directly target the listening HTTP endpoints of the Helidon application without needing prior reconnaissance or credential acquisition.\nThe step-by-step attack flow proceeds as follows: First, the attacker establishes network connectivity to the targeted Helidon HTTP server. Second, the attacker crafts and transmits a specific HTTP request designed to bypass intended access restrictions within the Imperative Web Server component. Third, the application processes the request and improperly returns data from the subset of Helidon accessible data to the unauthenticated client. Finally, the attacker captures the response, obtaining unauthorized read access to sensitive information.\nThe attack vector is classified as network-based (AV:N) with a low attack complexity (AC:L), meaning that standard network routing to the target service is sufficient for successful exploitation without requiring sophisticated timing or race conditions. The scope (S:U) remains unchanged, as the vulnerability is constrained to the affected Helidon component without directly impacting underlying host resources beyond the application data layer. The resulting CVSS 3.1 base score of 5.3 reflects this specific confidentiality impact (C:L), with no associated integrity (I:N) or availability (A:N) degradation."
}
CVE-2026-73871: Helidon Imperative Web Server Information Disclosure (MEDIUM Severity, CVSS: 5.3) - Sceawere