Sceawere
Vulnerability Detail
CVE-2026-73928UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Helidon Imperative Web Server Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Helidon
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-08-18T21:18:25.773Z",
"pubdate": "2026-08-18T21:18:25.773Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Imperative Web Server component of Oracle Fusion Middleware Helidon version 4.5.3, allowing unauthenticated remote attackers with network access via HTTP to compromise the targeted system. Successful exploitation of this vulnerability results in a scope change, potentially impacting additional products beyond the immediate Helidon deployment. The security flaw grants unauthorized read access to a subset of Helidon-accessible data, alongside unauthorized update, insert, or delete capabilities against specific data assets. The CVSS 3.1 base score is calculated at 7.2, reflecting high severity due to impacts on confidentiality and integrity without directly affecting system availability. Attackers require no privileges and no user interaction, making network-based exploitation straightforward against exposed endpoints. Organizations running the affected Oracle Helidon version face significant risk of data exposure and unauthorized data manipulation, necessitating immediate remediation once vendor patches are made available.",
"technicalDetails": "The vulnerability resides in the Imperative Web Server component of the Oracle Helidon product, specifically affecting version 4.5.3. The root cause stems from improper input validation or insufficient access control enforcement within the HTTP request handling pipeline of the web server. Because the vulnerability is exposed via the network (AV:N), an unauthenticated attacker (PR:N) with standard HTTP connectivity can interact directly with the vulnerable component without requiring prior authentication or user interaction (UI:N). The attack complexity is low (AC:L), indicating that the flaw can be reliably exploited without sophisticated conditions or race constraints. During the attack flow, a malicious actor crafts and transmits specifically crafted HTTP requests to the vulnerable Imperative Web Server endpoints. Due to the scope change (S:C) characteristic of this vulnerability, successful processing of these requests bypasses intended boundary restrictions, allowing the attacker to transcend the immediate Helidon application context and potentially impact secondary or adjacently integrated products. Post-exploitation impacts manifest as unauthorized data exposure, where sensitive subsets of Helidon-accessible data can be read, as well as data tampering capabilities, allowing unauthorized users to execute update, insert, or delete operations on protected data stores. The combination of low attack complexity, network vector, and lack of authentication prerequisites enables rapid automated exploitation by malicious actors scanning for unpatched Helidon deployments."
}