CRITICAL 9.4 CVE-2026-73920 Published 18 Aug 2026

Helidon Imperative Web Server Remote Vulnerability Allows Data Tampering and DoS

Worried this affects one of your servers?

A vulnerability has been reported in Helidon, a product of Oracle Fusion Middleware, specifically in its Imperative Web Server component. The flaw is an easily exploitable HTTP vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Helidon.

Affected versions are 4.0.0 through 4.4.1. Successful attacks can result in:

  • Unauthorized creation, deletion, or modification of critical data or all Helidon accessible data
  • Unauthorized access to critical data or complete access to all Helidon accessible data
  • Unauthorized partial denial of service (partial DoS) of Helidon

The vulnerability has a CVSS 3.1 base score of 9.4 (Confidentiality, Integrity, and Availability impacts), with vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).

Reference: CVE-2026-73920 on NVD

← Back to Security News