Sceawere

Vulnerability Detail

CVE-2026-73877UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Helidon Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-18T21:18:20.047Z",
  "pubdate": "2026-08-18T21:18:20.047Z",
  "executiveSummary": "An information disclosure vulnerability has been identified within the Imperative Web Server component of Oracle Fusion Middleware Helidon version 3.2.18. This security flaw allows unauthenticated remote attackers with network access via the HTTP protocol to compromise the confidentiality of the affected system. Successful exploitation of this vulnerability results in unauthorized read access to a subset of data accessible by Helidon. The vulnerability presents a CVSS 3.1 Base Score of 5.3, with impacts exclusively affecting confidentiality (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). The attack vector is network-based, characterized by low attack complexity, requiring no user interaction and no privileges. This enables adversaries to conduct reconnaissance or retrieve sensitive data directly exposed by the vulnerable web server component without authentication constraints.",
  "technicalDetails": "The vulnerability resides within the Imperative Web Server component of Oracle Helidon version 3.2.18. The root cause stems from improper handling or insufficient access controls during HTTP request processing, allowing unauthenticated remote clients to bypass intended security boundaries and retrieve data they should not be permitted to access. Exploitation is conducted entirely over the network via standard HTTP requests sent to the vulnerable service endpoints. Because the attack complexity is low and the vulnerability requires zero privileges or user interaction, an attacker can directly target the exposed HTTP listener of the Helidon instance. The attack flow begins with the adversary crafting and transmitting malicious or unstructured HTTP queries designed to trigger the underlying flaw in the request parsing or resource allocation logic of the Imperative Web Server. Upon processing the request, the vulnerable component fails to adequately enforce authorization checks, resulting in the leakage of internal data structures, configuration parameters, or application-level datasets. The payload behavior involves standard web traffic, making protocol-level anomaly detection challenging without deep packet inspection or application-layer awareness. The post-exploitation impact is strictly confined to confidentiality breaches, specifically unauthorized read access to a subset of Helidon accessible data, which may subsequently facilitate further targeted attacks against the underlying infrastructure."
}
CVE-2026-73877: Oracle Helidon Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere