Sceawere

Vulnerability Detail

CVE-2026-73900UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Information Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-18T21:18:22.660Z",
  "pubdate": "2026-08-18T21:18:22.660Z",
  "executiveSummary": "An information disclosure vulnerability has been identified within the Helidon product of Oracle Fusion Middleware, specifically affecting the Imperative Web Server component in version 4.5.1. This security flaw enables unauthenticated malicious actors with network access via the HTTP protocol to compromise the confidentiality of the affected deployment. Successful exploitation of this vulnerability directly results in unauthorized read access to a specific subset of data that is accessible through the Helidon framework.\nThe vulnerability is characterized by its low attack complexity and the absence of required privileges or user interaction, significantly lowering the barrier to entry for potential adversaries. From a risk perspective, exposure of sensitive internal data could lead to further compromise depending on the nature of the information disclosed. The vulnerability is strictly confined to confidentiality impacts, with no integrity or availability disruptions associated with the base vector.",
  "technicalDetails": "The vulnerability resides in the Imperative Web Server component of Oracle Fusion Middleware Helidon version 4.5.1. The root cause stems from improper input validation or insufficient access control enforcement within the HTTP request handling pipeline, allowing unauthenticated remote clients to bypass intended security boundaries and retrieve data they are not authorized to view.\nThe attack vector is network-based (AV:N), requiring the attacker to send specially crafted HTTP requests to the exposed Helidon endpoint. Exploitation requires low attack complexity (AC:L) and demands zero prior authentication (PR:N) as well as no user interaction (UI:N). The scope of the vulnerability remains unchanged (S:U), meaning the security domain is restricted to the vulnerable component itself without directly breaching external resources.\nDuring a typical attack flow, the adversary formulates a targeted HTTP request designed to probe or query the Imperative Web Server component. Due to the flaw in request processing or data exposure controls, the component fails to properly validate the authorization context of the incoming session. Consequently, the server processes the request and returns a response containing sensitive application data or internal state information. The payload behavior is strictly passive from an execution standpoint, focusing entirely on data exfiltration rather than code execution or system modification. The resulting post-exploitation impact is limited to unauthorized read access (C:L), exposing a subset of Helidon-accessible data to unauthorized external entities."
}
CVE-2026-73900: Helidon Imperative Web Server Information Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere