Sceawere

Vulnerability Detail

CVE-2026-73919UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 3.2.18. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-18T21:18:24.853Z",
  "pubdate": "2026-08-18T21:18:24.853Z",
  "executiveSummary": "An easily exploitable vulnerability affecting the Imperative Web Server component of Oracle Fusion Middleware Helidon version 3.2.18 allows low privileged remote attackers to compromise the system via HTTP network access.\nSuccessful exploitation of this vulnerability leads to unauthorized confidentiality and integrity impacts, granting attackers the ability to perform unauthorized read, update, insert, or delete operations against a subset of Helidon accessible data.\nThe vulnerability carries a CVSS 3.1 Base Score of 5.4 with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N, indicating that network attack vectors and low privileges are prerequisites for a successful compromise.\nRisk implications include data exposure and unauthorized data manipulation within the application context, necessitating prompt remediation to prevent integrity and confidentiality breaches.",
  "technicalDetails": "The vulnerability resides within the Imperative Web Server component of the Helidon product, specifically impacting version 3.2.18.\nAttackers require network access via the HTTP protocol to interact with the vulnerable endpoint, along with low privileges to authenticate against the affected system.\nThe exploitation method involves sending maliciously crafted HTTP requests that bypass intended access controls enforced by the Imperative Web Server.\nStep-by-step attack flow begins with the low-privileged attacker establishing a network connection to the Helidon HTTP service. The attacker crafts an arbitrary HTTP request targeting sensitive or improperly restricted resources managed by the Imperative Web Server. Due to insufficient authorization checks within the vulnerable component, the server processes the request and executes the requested data operations without verifying if the authenticated low-privileged user possesses the requisite permissions.\nPost-exploitation impact includes unauthorized read access to a subset of Helidon accessible data, compromising confidentiality, as well as unauthorized update, insert, or delete access to data, compromising data integrity.\nAvailability impacts are none, meaning the vulnerability does not directly lead to denial of service conditions under the specified CVSS vector."
}
CVE-2026-73919: Helidon Imperative Web Server Vulnerability (MEDIUM Severity, CVSS: 5.4) - Sceawere