CRITICAL
9.8 CVE-2026-71152 Published 18 Aug 2026
Helidon Imperative Web Server Remote Takeover Vulnerability
Worried this affects one of your servers?
Oracle has disclosed a vulnerability in the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component. The flaw is an easily exploitable remote takeover issue that allows an unauthenticated attacker with network access via HTTP to compromise Helidon.
Affected versions include:
- Helidon 3.0.0 through 3.2.17
- Helidon 4.0.0 through 4.4.1
Successful attacks can result in full takeover of Helidon, with high impact to confidentiality, integrity, and availability. The CVSS 3.1 base score is 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Reference: CVE-2026-71152 on NVD
← Back to Security News