CRITICAL
9.8 CVE-2026-71164 Published 18 Aug 2026
Helidon Imperative Web Server Remote Takeover Vulnerability
Worried this affects one of your servers?
A vulnerability has been reported in the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component. Supported versions affected are 3.0.0 through 3.2.17.
The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, and successful attacks can result in takeover of Helidon.
- Affected versions: 3.0.0-3.2.17
- Attack vector: network access via HTTP, no authentication required
- Impact: complete takeover of Helidon, with high confidentiality, integrity, and availability impacts
- CVSS 3.1 Base Score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Reference: CVE-2026-71164 on NVD
← Back to Security News