CRITICAL 9.9 CVE-2026-73930 Published 18 Aug 2026

Helidon Imperative Web Server HTTP Vulnerability

Worried this affects your website?

A vulnerability has been reported in Helidon, specifically in its Imperative Web Server component. The flaw is an easily exploitable HTTP-based vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Helidon.

Affected versions are:

  • Helidon 3.0.0 through 3.2.19
  • Helidon 4.0.0 through 4.5.2

Successful attacks can result in:

  • Unauthorized creation, deletion or modification access to critical data or all Helidon accessible data
  • Unauthorized read access to a subset of Helidon accessible data
  • Unauthorized partial denial of service (partial DoS) of Helidon

Attacks may significantly impact additional products (scope change). CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L).

Reference: CVE-2026-73930 on NVD

← Back to Security News