Sceawere

Vulnerability Detail

CVE-2026-73872UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-18T21:18:19.453Z",
  "pubdate": "2026-08-18T21:18:19.453Z",
  "executiveSummary": "A vulnerability has been identified in the Helidon product of Oracle Fusion Middleware, specifically within the Imperative Web Server component. This flaw allows an unauthenticated remote attacker to compromise the confidentiality of the system by exploiting the application over the network via HTTP.\nThe vulnerability directly impacts Oracle Fusion Middleware Helidon version 4.5.0. Successful exploitation results in unauthorized read access to a subset of data accessible via Helidon, posing a moderate risk to information confidentiality while leaving data integrity and system availability unaffected.\nFrom an attacker's perspective, the vulnerability requires no privileges, no user interaction, and minimal complexity to exploit. The attack vector is entirely network-based, meaning any unauthenticated adversary with standard HTTP connectivity to the vulnerable endpoint can initiate an attack.\nThe risk implication centers on unauthorized data exposure, where sensitive subsets of application data may be harvested by malicious actors without leaving traditional authentication footprints. Because the vulnerability is easily exploitable over the network, organizations utilizing the affected version of Helidon face a heightened exposure window until remediation is applied.",
  "technicalDetails": "The vulnerability resides within the Imperative Web Server component of Oracle Fusion Middleware Helidon version 4.5.0. The root cause stems from improper handling or insufficient access controls within HTTP request processing, which allows external actors to bypass intended authorization boundaries.\nThe attack flow begins when an unauthenticated attacker crafts a specific HTTP request directed at the vulnerable Helidon Imperative Web Server endpoint. Due to the lack of adequate input validation or authorization checks within the affected component, the server processes the request and improperly returns data that should otherwise be restricted.\nBecause the vulnerability is exposed via the network (AV:N), exploitation requires only standard HTTP connectivity. The attack complexity is rated as low (AC:L), indicating that no specialized race conditions, memory corruption techniques, or complex cryptographic manipulations are required to trigger the flaw. Furthermore, the attack requires zero privileges (PR:N) and zero user interaction (UI:N), allowing automated scanners or malicious scripts to execute the request seamlessly.\nThe payload behavior involves probing or directly querying sensitive URI paths or parameters handled by the Imperative Web Server that lack proper confinement. Upon successful processing of the malicious request, the server responds with data subsets accessible to the application context.\nThe post-exploitation impact is strictly limited to unauthorized read access (C:L), resulting in a CVSS 3.1 Base Score of 5.3 with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. There is no impact on system integrity (I:N) or availability (A:N), meaning the vulnerability cannot be leveraged to execute arbitrary code, modify data, or cause denial-of-service conditions."
}
CVE-2026-73872: Helidon Imperative Web Server Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere