CVE-2026-71160: High severity Oracle Helidon (Oracle Fusion Middleware: Imperative Web Server) vulnerability
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18 and 3.0.0-3.2.17. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access to the Helidon Imperative Web Server over HTTP and must already have low-privileged access. No user interaction is required, but exploitation is rated difficult.
Which deployments are identified as affected?
The affected supported version identified is Oracle Helidon 3.2.18 in Oracle Fusion Middleware's Imperative Web Server component.
What is the potential impact of successful exploitation?
Successful exploitation can result in takeover of Helidon, with high confidentiality, integrity, and availability impact.