CVE-2026-73911: Medium severity Oracle Helidon vulnerability
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data as well as unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Helidon (Oracle Fusion Middleware) - Imperative Web Serverto a version that resolves this vulnerability.Fixed in 4.4.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs low-privileged access and network reachability to the affected Helidon service over HTTP. No user interaction is required, and the attack complexity is low.
Which deployments are known to be affected?
The affected component is the Imperative Web Server in Oracle Helidon. The supported affected version identified is 4.5.0.
What could a successful attacker access or change?
Successful exploitation can allow unauthorized read access to a subset of data accessible to Helidon. It can also allow unauthorized updates, inserts, or deletes involving some Helidon-accessible data.