CRITICAL 9.1 CVE-2026-73865 Published 18 Aug 2026

Helidon Imperative Web Server HTTP Data Tampering and Exposure Vulnerability

Worried this affects one of your servers?

A vulnerability has been reported in Helidon, an Oracle Fusion Middleware product, specifically in the Imperative Web Server component. Supported affected versions are 3.0.0 through 3.2.17.

The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful attacks can compromise Helidon, resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all Helidon-accessible data.

  • CVSS 3.1 Base Score: 9.1 (Confidentiality and Integrity impacts)
  • CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Reference: CVE-2026-73865 on NVD

← Back to Security News