Sceawere

Vulnerability Detail

CVE-2026-73931UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Helidon Imperative Web Server Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.3
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Helidon
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.3",
  "pubDate": "2026-08-18T21:18:26.113Z",
  "pubdate": "2026-08-18T21:18:26.113Z",
  "executiveSummary": "An easily exploitable vulnerability affects the Imperative Web Server component of Oracle Fusion Middleware Helidon version 4.5.3. This vulnerability allows an unauthenticated remote attacker with network access via HTTP to compromise the Helidon environment. Due to a scope change, successful attacks can significantly impact additional products beyond the primary vulnerable component. The exploitation results in unauthorized read access to a subset of Helidon accessible data, unauthorized update, insert, or delete access to some data, and the ability to trigger a partial denial of service (partial DOS) affecting Helidon availability. The CVSS 3.1 base score is 8.3, reflecting severe impacts across confidentiality, integrity, and availability. Attack execution requires no user interaction and low attack complexity, making it an urgent risk for deployments running the affected version.",
  "technicalDetails": "The vulnerability resides within the Imperative Web Server component of the Helidon product, specifically impacting version 4.5.3. The root cause enables remote manipulation or unauthorized interaction via HTTP without requiring any prior authentication or privileges. The attack vector is strictly network-based (AV:N), meaning any remote threat actor with standard HTTP connectivity to the target service can initiate exploitation. The attack complexity is rated as low (AC:L), and zero user interaction (UI:N) is required, indicating that automated scripts or direct HTTP payloads can successfully trigger the flaw.\nDuring the attack flow, the adversary crafts malicious HTTP requests directed at the vulnerable Imperative Web Server component. Upon receipt and processing of these requests, the application fails to adequately validate or restrict input or state handling, leading to a breach of security boundaries. Because the vulnerability features a scope change (S:C), the compromise extends beyond the immediate boundary of the Helidon runtime, potentially impacting external or integrated products within the broader Oracle Fusion Middleware architecture.\nThe post-exploitation impact spans multiple security dimensions. Confidentiality is impacted (C:L) by granting unauthorized read access to a subset of data accessible to Helidon. Integrity is compromised (I:L) through unauthorized update, insert, or delete operations performed against Helidon accessible data. Availability is degraded (A:L) via the execution of payload behaviors that induce a partial denial of service condition, disrupting normal server operations and service responsiveness. All conditions manifest through standard network protocols leveraging standard HTTP primitives."
}
CVE-2026-73931: Helidon Imperative Web Server Vulnerability (HIGH Severity, CVSS: 8.3) - Sceawere