Sceawere

Vulnerability Detail

CVE-2026-73875UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-18T21:18:19.807Z",
  "pubdate": "2026-08-18T21:18:19.807Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Imperative Web Server component of Oracle Fusion Middleware Helidon, specifically affecting supported version 3.2.19. This security flaw allows unauthenticated threat actors with network access via the HTTP protocol to successfully compromise the target Helidon instance.\nThe vulnerability possesses a CVSS 3.1 Base Score of 7.2 with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N, indicating that network exploitation requires low attack complexity without necessitating any authentication or user interaction. A critical characteristic of this security issue is its scope change, meaning that successful exploitation within Helidon can generate significant cascading impacts against additional integrated or dependent products.\nFrom a risk perspective, successful exploitation enables unauthorized threat actors to execute data modification routines, specifically granting unauthorized update, insert, or delete access to a subset of Helidon accessible data. Additionally, attackers can achieve unauthorized read access to sensitive information subsets contained within the application ecosystem. Consequently, this vulnerability poses severe threats to data integrity and confidentiality across the deployment infrastructure.",
  "technicalDetails": "The vulnerability resides in the Imperative Web Server component of the Helidon product, specifically impacting version 3.2.19. The root cause stems from insufficient access controls or improper handling of incoming HTTP requests processed by the Imperative Web Server, permitting unauthorized operations against application-accessible data stores.\nThe attack vector is network-based via HTTP, requiring no privileges (PR:N) and no user interaction (UI:N) with a low attack complexity (AC:L). Because the vulnerability is exposed directly over the network, any unauthenticated remote attacker capable of establishing an HTTP connection to the Helidon service can initiate malicious request payloads.\nThe step-by-step attack flow initiates when the attacker crafts a malicious HTTP request designed to bypass intended authorization boundaries enforced by the Imperative Web Server. The attacker transmits this unauthenticated request over the network to the exposed Helidon endpoint. Upon reception, the vulnerable component improperly parses or validates the request context, failing to enforce strict access restrictions.\nThis processing failure allows the attacker's payload to interact directly with internal data resources. Post-exploitation impact includes the execution of unauthorized read operations against confidential data subsets, alongside unauthorized write, update, insertion, or deletion operations against mutable data sets accessible to Helidon.\nDue to the scope change (S:C) vector characteristic, the architectural impact extends beyond the immediate boundaries of the Helidon runtime environment. Successfully executed attacks can propagate security consequences to additional downstream or upstream products integrated within the Oracle Fusion Middleware ecosystem, compounding the overall severity of the compromise."
}
CVE-2026-73875: Helidon Imperative Web Server Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere