CRITICAL 9.8 CVE-2026-73905 Published 18 Aug 2026

Helidon Imperative Web Server Remote Takeover Vulnerability

Worried this affects one of your servers?

A vulnerability has been reported in the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component. The flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Helidon.

Successful attacks can result in a full takeover of Helidon. The affected versions are 4.0.0 through 4.4.1.

  • CVSS 3.1 Base Score: 9.8 (Critical)
  • Impact: High confidentiality, integrity, and availability impacts
  • CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference: CVE-2026-73905 on NVD

← Back to Security News