CRITICAL 9.3 CVE-2026-71065 Published 18 Aug 2026

Helidon Imperative Web Server HTTP Vulnerability

Worried this affects one of your servers?

A vulnerability has been disclosed in Helidon, part of Oracle Fusion Middleware, specifically in the Imperative Web Server component. The flaw is an easily exploitable HTTP vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Helidon.

Affected versions are 3.0.0 through 3.2.17. The vulnerability has a scope change, meaning attacks may significantly impact additional products beyond Helidon itself.

  • Unauthenticated attacker with network access via HTTP
  • Can result in unauthorized access to critical data or complete access to all Helidon-accessible data
  • Can also allow unauthorized update, insert, or delete access to some Helidon-accessible data
  • CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts)
  • CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N)

Reference: CVE-2026-71065 on NVD

← Back to Security News