CVE-2026-73915: High severity Oracle Oracle Fusion Middleware (Helidon) - Imperative Web Server vulnerability
Published Aug 18, 2026
·Updated
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
2 affected components
Oracle Oracle Fusion Middleware (Helidon) - Imperative Web Server=4.5.0
Oracle Helidon=4.5.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Fusion Middleware Helidon (Imperative Web Server)to a version that resolves this vulnerability.Fixed in 4.4.1
Event History
Aug 18, 2026
CVE Published
via MITRE·09:04 PM
Data Sourced
via MITRE·09:04 PM
DescriptionSeverity
Data Sourced
via NVD·09:18 PM
DescriptionSeverityWeaknessAffected Software