Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-73930: Oracle Helidon Imperative Web Server Allows Unauthorized Access

CVE-2026-73930 · published 16 days ago
Summary

An attacker can access sensitive data and disrupt Oracle Helidon without a password. This affects Helidon version 4.5.3 and potentially other products. Update Helidon to a fixed version to prevent unauthorized access and disruptions.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
oracle corporation helidon 4.5.3
Original advisory text
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unaut...
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).
Severity
9.9 Critical
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-284Improper Access Control
Timeline
Published18 Aug 2026
Updated30 Aug 2026
First seen18 Aug 2026
Sources
CVE-2026-73930 · MITRE
Monitor software like this
Free during beta