CRITICAL
9.1 CVE-2026-73916 Published 18 Aug 2026
Helidon Imperative Web Server Flaw Lets Remote Attackers Access and Modify Data
Worried this affects one of your servers?
A remote data access and integrity vulnerability affects the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component.
Supported versions 3.0.0 through 3.2.17 are affected. The flaw is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise Helidon.
- Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Helidon accessible data.
- Successful attacks can also result in unauthorized access to critical data or complete access to all Helidon accessible data.
- CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).
Reference: CVE-2026-73916 on NVD
← Back to Security News