CRITICAL 9.1 CVE-2026-73922 Published 18 Aug 2026

Helidon Imperative Web Server Unauthorized Data Access Vulnerability

Worried this affects your website?

A vulnerability has been reported in Helidon, an Oracle Fusion Middleware product, specifically in the Imperative Web Server component. The flaw is an unauthorized data access and modification vulnerability. Affected versions are 1.0.0 through 1.4.18.

  • The vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP.
  • Successful attacks can compromise Helidon, resulting in unauthorized creation, deletion, or modification of critical data, or all Helidon accessible data.
  • It can also lead to unauthorized access to critical data, or complete access to all Helidon accessible data.
  • CVSS 3.1 Base Score is 9.1, with Confidentiality and Integrity impacts. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Reference: CVE-2026-73922 on NVD

← Back to Security News