CVE-2026-73939: High severity Oracle Helidon vulnerability
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 8.6 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for triage?
Oracle Helidon deployments using the Imperative Web Server component on supported version 3.2.20 should be prioritized.
Does exploitation require credentials or user interaction?
No. An unauthenticated attacker with network access over HTTP can exploit the issue; no user interaction is required.
What is the likely outcome of a successful attack?
A successful attack can allow unauthorized creation, deletion, or modification of critical data or all data accessible through Helidon. The impact may also significantly affect additional products because the vulnerability has scope change.