CRITICAL
9.1 CVE-2026-73865 Published 18 Aug 2026
Helidon Imperative Web Server HTTP Data Tampering and Exposure Vulnerability
Worried this affects one of your servers?
A vulnerability has been reported in Helidon, an Oracle Fusion Middleware product, specifically in the Imperative Web Server component. Supported affected versions are 3.0.0 through 3.2.17.
The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful attacks can compromise Helidon, resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all Helidon-accessible data.
- CVSS 3.1 Base Score: 9.1 (Confidentiality and Integrity impacts)
- CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Reference: CVE-2026-73865 on NVD
← Back to Security News