CRITICAL 9.4 CVE-2026-71166 Published 18 Aug 2026

Helidon Imperative Web Server Critical HTTP Vulnerability

Worried this affects one of your servers?

A vulnerability has been found in the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component. Supported versions 3.0.0 through 3.2.17 are affected.

The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, and can compromise Helidon.

Successful attacks may result in:

  • Unauthorized creation, deletion, or modification of critical data or all Helidon accessible data
  • Unauthorized access to critical data or complete access to all Helidon accessible data
  • Unauthorized partial denial of service (partial DoS) of Helidon

The CVSS 3.1 base score is 9.4, with high confidentiality and integrity impacts and low availability impact.

Reference: CVE-2026-71166 on NVD

← Back to Security News