CVE-2026-73923: Low severity Oracle Helidon vulnerability
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Instances running the affected supported Helidon version 1.4.20 are exposed if an attacker can reach the Imperative Web Server over HTTP. No authentication or user interaction is required, but exploitation has high attack complexity.
What could a successful attacker do?
A successful unauthenticated network attacker could gain unauthorized ability to update, insert, or delete some data accessible through Helidon. The stated impact is limited to integrity; no confidentiality or availability impact is listed.