Sceawere

Vulnerability Detail

CVE-2026-73886UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-18T21:18:21.067Z",
  "pubdate": "2026-08-18T21:18:21.067Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Oracle Fusion Middleware product Helidon, specifically affecting the Imperative Web Server component in version 4.5.0. This security flaw enables an unauthenticated remote attacker with network access via HTTP to compromise the targeted Helidon instance. Due to a change in the security scope, successful exploitation of this vulnerability extends its impact beyond the primary component, potentially affecting additional integrated products.\nThe primary risk implications include unauthorized data manipulation and exposure. Specifically, successful attacks can result in unauthorized update, insert, or delete access to a subset of data accessible by Helidon, alongside unauthorized read access to sensitive subset data. The vulnerability carries a CVSS 3.1 Base Score of 7.2 with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N, reflecting network exploitability with low attack complexity, requiring no privileges or user interaction, and yielding confidentiality and integrity impacts with a changed scope.",
  "technicalDetails": "The vulnerability resides in the Imperative Web Server component of Oracle Helidon version 4.5.0. The root cause allows unauthenticated remote attackers to interact with vulnerable endpoints over HTTP, bypassing expected authorization controls and access boundary restrictions. Because the attack vector is network-based (AV:N), adversaries do not require local access or physical proximity to the target system.\nThe attack flow proceeds as follows: an unauthenticated attacker crafts malicious HTTP requests directed at the exposed network ports of the Helidon Imperative Web Server. Owing to the low attack complexity (AC:L) and the absence of required privileges (PR:N) or user interaction (UI:N), the server processes the incoming request without validating the caller's authorization state. The lack of proper input validation or context enforcement within the Imperative Web Server permits the attacker to interact with backend data structures.\nUpon successful payload delivery and processing, the security scope change (S:C) allows the impact to ripple across domain boundaries, affecting additional products beyond the immediate Helidon instance. Post-exploitation impacts are characterized by unauthorized data operations, specifically granting the attacker capabilities to perform insert, update, and delete actions against accessible data repositories, as well as executing unauthorized read operations to extract subsets of sensitive information managed or processed by Helidon. The availability impact remains unaffected (A:N), as the attack focuses strictly on data confidentiality and integrity breaches rather than denial of service."
}
CVE-2026-73886: Oracle Helidon Imperative Web Server Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere