CRITICAL
9.4 CVE-2026-71167 Published 18 Aug 2026
Helidon Imperative Web Server HTTP Request Handling Vulnerability
Worried this affects one of your servers?
A vulnerability has been disclosed in Helidon, Oracle Fusion Middleware's Imperative Web Server component. Affected versions are 4.0.0 through 4.4.1. The flaw is an HTTP request handling vulnerability that is easily exploitable by an unauthenticated attacker with network access via HTTP.
Successful attacks can compromise Helidon and lead to:
- Unauthorized creation, deletion, or modification of critical data or all Helidon-accessible data
- Unauthorized access to critical data or complete access to all Helidon-accessible data
- Unauthorized partial denial of service (partial DoS) of Helidon
The vulnerability has a CVSS 3.1 base score of 9.4 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L.
Reference: CVE-2026-71167 on NVD
← Back to Security News