CRITICAL
9.8 CVE-2026-73921 Published 18 Aug 2026
Helidon Imperative Web Server Remote Takeover Vulnerability
Worried this affects one of your servers?
Oracle has disclosed a vulnerability in Helidon, specifically in its Imperative Web Server component. The flaw is a remote takeover vulnerability that affects Helidon versions 1.0.0 through 1.4.19.
An unauthenticated attacker with network access via HTTP can exploit this issue to compromise Helidon. Successful attacks can result in full takeover of the affected server.
- Affected versions: 1.0.0-1.4.19
- Attack vector: network access via HTTP, no authentication required
- CVSS 3.1 Base Score: 9.8 (Critical)
- Impact: high confidentiality, integrity, and availability impacts
Reference: CVE-2026-73921 on NVD
← Back to Security News