CRITICAL 9.1 CVE-2026-73924 Published 18 Aug 2026

Helidon Imperative Web Server Unauthorized Data Access Vulnerability

Worried this affects one of your servers?

A vulnerability has been reported in Helidon, a product of Oracle Fusion Middleware, specifically in the Imperative Web Server component. This unauthorized data access and modification vulnerability is easily exploitable by an unauthenticated attacker with network access via HTTP.

Affected versions are 1.0.0 through 1.4.18. Successful attacks can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical data or complete access to all Helidon-accessible data.

  • Affected versions: 1.0.0-1.4.18
  • Attack vector: network access via HTTP, no authentication required
  • Impact: unauthorized creation, deletion, or modification of critical data; unauthorized access to critical data
  • CVSS 3.1 Base Score: 9.1 (Confidentiality and Integrity impacts)
  • CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Reference: CVE-2026-73924 on NVD

← Back to Security News