CRITICAL 9.8 CVE-2026-71074 Published 18 Aug 2026

Helidon Imperative Web Server Unauthenticated Takeover Vulnerability

Worried this affects one of your servers?

A critical unauthenticated takeover vulnerability has been disclosed in the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component.

Supported versions affected are:

  • Helidon 1.0.0 through 1.4.19
  • Helidon 3.0.0 through 3.2.17

The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP and can result in full takeover of Helidon. It has a CVSS 3.1 base score of 9.8 with high confidentiality, integrity, and availability impacts. The CVSS vector is (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Reference: CVE-2026-71074 on NVD

← Back to Security News