Sceawere
Vulnerability Detail
CVE-2026-73893UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Helidon Imperative Web Server Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Helidon
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-18T21:18:21.870Z",
"pubdate": "2026-08-18T21:18:21.870Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Imperative Web Server component of Oracle Fusion Middleware Helidon version 4.5.0. This security flaw enables unauthenticated malicious actors with network access via HTTP to compromise the affected Helidon instance. Successful exploitation of this vulnerability can lead to unauthorized data manipulation, including the update, insertion, or deletion of accessible data, alongside unauthorized read access to a specific subset of sensitive data managed by the application. The vulnerability carries a CVSS 3.1 Base Score of 6.5, reflecting moderate-to-high severity driven exclusively by impacts to confidentiality and integrity, with no availability disruption reported. The attack vector is strictly network-based, requiring low attack complexity without necessitating user interaction or any prior authentication privileges. Consequently, the risk implications are significant for exposed deployments, as external adversaries can bypass security boundaries to compromise data integrity and confidentiality without needing internal credentials or advanced social engineering tactics.",
"technicalDetails": "The vulnerability resides in the Imperative Web Server component of the Helidon product, specifically affecting version 4.5.0. The root cause stems from improper input validation, access control enforcement, or request processing logic within the HTTP request handling pipeline of the web server engine. Because the vulnerability is exposed directly via the network layer using the HTTP protocol, any remote actor capable of routing traffic to the target endpoint can interact with the vulnerable component.\nExploitation does not require authentication or user interaction, meaning an attacker can script automated payloads and transmit them directly to the web server interface. The attack flow commences when the malicious client crafts specialized HTTP requests designed to bypass existing logical constraints within the Imperative Web Server. Upon receipt, the vulnerable component fails to properly validate or restrict the scope of the request, processing the inputs in a manner that grants unauthorized access to internal resources and backend data repositories.\nThe payload behavior leverages standard HTTP methods to target exposed API endpoints or internal routing mechanisms. Post-exploitation impact encompasses unauthorized read access to a subset of Helidon accessible data, allowing the extraction of sensitive information. Furthermore, the attacker gains unauthorized update, insert, or delete access to additional portions of Helidon accessible data, potentially leading to persistent data corruption, unauthorized state modification, or integrity violations within the application's operational data store. The vector parameters dictate an attack complexity of low, emphasizing that the flaw is reliably reproducible when network connectivity is established to the target instance."
}