CVE-2026-73883: Infoleak
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Oracle Helidon deployments using the Imperative Web Server component in supported version 3.2.18 are identified as affected. Exposure requires network reachability to the server over HTTP.
Does exploitation require authentication or user interaction?
No. An unauthenticated attacker can exploit the issue remotely over HTTP, and no user interaction is required.
What is the likely impact of successful exploitation?
Successful exploitation can provide unauthorized access to critical data or complete access to all data accessible to Helidon. The reported impact is confidentiality only; integrity and availability impacts are not listed.