Sceawere

Vulnerability Detail

CVE-2026-73930UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-08-18T21:18:26.003Z",
  "pubdate": "2026-08-18T21:18:26.003Z",
  "executiveSummary": "An easily exploitable vulnerability affects the Helidon product of Oracle Fusion Middleware, specifically within the Imperative Web Server component in version 4.5.3. This security flaw allows an unauthenticated remote attacker with network access via HTTP to compromise the affected system.\nThe vulnerability features a scope change, meaning successful exploitation may significantly impact additional products beyond Helidon itself. The attack capabilities include unauthorized creation, deletion, or modification access to critical data and all Helidon accessible data, unauthorized read access to a subset of Helidon accessible data, and the ability to cause a partial denial of service (partial DoS).\nGiven the CVSS 3.1 Base Score of 9.9, this vulnerability presents severe risk implications across confidentiality, integrity, and availability metrics. Exploitation requires no privileges, no user interaction, and low attack complexity, making network-based HTTP vectors highly critical.",
  "technicalDetails": "The vulnerability resides in the Imperative Web Server component of the Helidon product within Oracle Fusion Middleware, specifically affecting version 4.5.3. The root cause enables unauthenticated remote attackers to leverage network access via HTTP to interact with vulnerable handlers or parsing routines.\nExploitation is achieved over the network via standard HTTP requests without requiring any pre-existing authentication credentials or user interaction. The attack complexity is classified as low, indicating that an attacker can reliably execute the exploit vector without specialized conditions.\nThe attack flow proceeds as follows: First, the unauthenticated attacker crafts a malicious HTTP request directed at the network-exposed Imperative Web Server of the target Helidon deployment. Second, upon receiving the request, the vulnerable component improperly processes the input due to insufficient validation or access controls. Third, the crafted payload triggers unintended execution logic or unauthorized resource manipulation.\nBecause the vulnerability involves a scope change (S:C), the impact extends beyond the immediate boundary of the Helidon runtime, potentially affecting downstream or integrated products within the same administrative or architectural scope. Post-exploitation impacts include unauthorized create, delete, and modify operations against critical data and all accessible Helidon data, unauthorized read access to a subset of sensitive data, and a partial denial of service condition degrading service availability."
}
CVE-2026-73930: Helidon Imperative Web Server Vulnerability (CRITICAL Severity, CVSS: 9.9) - Sceawere