Sceawere

Vulnerability Detail

CVE-2026-73898UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-08-18T21:18:22.440Z",
  "pubdate": "2026-08-18T21:18:22.440Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Imperative Web Server component of Oracle Fusion Middleware Helidon version 4.5.0. This security flaw allows unauthenticated remote threat actors with network access via HTTP to compromise the affected Helidon deployment.\nSuccessful exploitation of this vulnerability requires human interaction from a victim other than the attacker. Due to a scope change, successful attacks may significantly impact additional products beyond the primary Helidon boundary.\nThe operational impact includes unauthorized read access to a subset of Helidon accessible data, alongside unauthorized update, insert, or delete access to some accessible data. The vulnerability carries a CVSS 3.1 Base Score of 6.1, driven by moderate confidentiality and integrity impacts with no availability disruption.\nRisk implications center around data exposure and unauthorized modification of application state, necessitating immediate attention to prevent malicious data tampering or information disclosure via network vectors.",
  "technicalDetails": "The vulnerability resides in the Imperative Web Server component of the Helidon product, specifically affecting version 4.5.0. The root cause enables unauthorized data manipulation and retrieval through improperly handled HTTP requests processed by the server.\nAttackers leverage network access via the HTTP protocol to interact with the vulnerable Helidon instance. Exploitation is categorized as easily exploitable, requiring low attack complexity and no prior authentication or administrative privileges.\nThe attack flow requires human interaction, meaning an authenticated or visiting user other than the attacker must perform a specific action—such as clicking a malicious link or interacting with a crafted web page—to trigger the vulnerability within their context.\nBecause the Common Vulnerability Scoring System (CVSS) vector indicates a scope change (S:C), the vulnerability allows an attacker to impact resources beyond the immediate security scope of the Helidon component, potentially affecting integrated or downstream products.\nPost-exploitation impacts involve unauthorized confidentiality and integrity breaches. Specifically, attackers can execute unauthorized update, insert, or delete operations against targeted data accessible to Helidon, as well as gain unauthorized read access to a subset of sensitive data residing within the application boundary.\nThe attack vector is entirely network-based (AV:N), requiring no local access, physical presence, or pre-existing privileges (PR:N), though reliance on user interaction (UI:R) serves as a necessary precondition for successful payload execution."
}
CVE-2026-73898: Oracle Helidon Imperative Web Server Vulnerability (MEDIUM Severity, CVSS: 6.1) - Sceawere