Sceawere

Vulnerability Detail

CVE-2026-73897UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:18:22.327Z",
  "pubdate": "2026-08-18T21:18:22.327Z",
  "executiveSummary": "An easily exploitable vulnerability affecting the Imperative Web Server component of Oracle Fusion Middleware Helidon version 4.5.0 allows unauthenticated remote attackers to compromise the system over the network via HTTP.\nThe security flaw leads to unauthorized data access and modification, directly impacting the confidentiality and integrity of accessible data within the Helidon environment.\nSuccessful exploitation grants an adversary unauthorized update, insert, or delete capabilities alongside unauthorized read access to a subset of Helidon accessible data.\nThe risk implications are significant due to the lack of required authentication, privileges, or user interaction, lowering the barrier to entry for potential threat actors.\nExploitation requirements are minimal, as the vulnerability is exposed via network vectors with low attack complexity, enabling unauthenticated threat actors to interact directly with the vulnerable Imperative Web Server component.",
  "technicalDetails": "The vulnerability resides within the Imperative Web Server component of the Oracle Fusion Middleware Helidon product, specifically targeting version 4.5.0.\nThe attack vector is network-based (AV:N), requiring low attack complexity (AC:L) without necessitating any prior authentication (PR:N) or user interaction (UI:N) under a scope-unchanged (S:U) security context.\nThe primary impact metrics correspond to a CVSS 3.1 Base Score of 6.5, driven by partial confidentiality (C:L) and integrity (I:L) impacts, with availability remaining unaffected (A:N).\nExploitation occurs when an unauthenticated attacker crafts malicious HTTP requests directed at the network-exposed Imperative Web Server.\nBecause the vulnerability stems from improper handling or insufficient access controls within the affected web server component, the crafted HTTP payloads bypass intended security boundaries.\nUpon receiving the malicious HTTP traffic, the vulnerable component processes the request without validating the attacker's authorization state.\nThis flawed processing sequence allows the attacker to execute unauthorized operations, specifically resulting in the unauthorized insertion, updating, or deletion of specific Helidon accessible data.\nConcurrently, the interaction permits the retrieval of restricted information, granting the attacker unauthorized read access to a subset of sensitive data managed or accessible by Helidon.\nThe post-exploitation impact is constrained to the subset of data accessible through the compromised Imperative Web Server interfaces, but still represents a critical breach of data integrity and confidentiality."
}
CVE-2026-73897: Helidon Imperative Web Server Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere