CRITICAL 9.8 CVE-2026-73921 Published 18 Aug 2026

Helidon Imperative Web Server Remote Takeover Vulnerability

Worried this affects one of your servers?

Oracle has disclosed a vulnerability in Helidon, specifically in its Imperative Web Server component. The flaw is a remote takeover vulnerability that affects Helidon versions 1.0.0 through 1.4.19.

An unauthenticated attacker with network access via HTTP can exploit this issue to compromise Helidon. Successful attacks can result in full takeover of the affected server.

  • Affected versions: 1.0.0-1.4.19
  • Attack vector: network access via HTTP, no authentication required
  • CVSS 3.1 Base Score: 9.8 (Critical)
  • Impact: high confidentiality, integrity, and availability impacts

Reference: CVE-2026-73921 on NVD

← Back to Security News