CRITICAL 9.1 CVE-2026-73917 Published 18 Aug 2026

Helidon Imperative Web Server Unauthorized Data Access Vulnerability

Worried this affects one of your servers?

A vulnerability has been reported in Helidon's Imperative Web Server that allows unauthorized data access and modification. Affected versions are 4.0.0 through 4.4.1.

The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP, and can compromise Helidon. Successful attacks may result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all Helidon-accessible data.

  • Affected versions: 4.0.0-4.4.1
  • CVSS 3.1 Base Score: 9.1 (Confidentiality and Integrity impacts)
  • CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Reference: CVE-2026-73917 on NVD

← Back to Security News