Oracle Helidon vulnerabilities
104 known vulnerabilities affecting oracle/helidon.
Total CVEs
104
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH41MEDIUM44LOW2
Vulnerabilities
Page 1 of 6
CVE-2026-71152P2CRITICALCVSS 9.8v4.5.02026-08-18
CVE-2026-71152 [CRITICAL] CWE-284 CVE-2026-71152: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17 and 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeo
nvd
CVE-2026-71164P2CRITICALCVSS 9.8v3.2.182026-08-18
CVE-2026-71164 [CRITICAL] CWE-284 CVE-2026-71164: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon.
nvd
CVE-2026-71074P2CRITICALCVSS 9.8v3.2.182026-08-18
CVE-2026-71074 [CRITICAL] CWE-284 CVE-2026-71074: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19 and 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in take
nvd
CVE-2026-73912P2CRITICALCVSS 9.8v4.5.02026-08-18
CVE-2026-73912 [CRITICAL] CWE-284 CVE-2026-73912: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. C
nvd
CVE-2026-73921P2CRITICALCVSS 9.8v1.4.202026-08-18
CVE-2026-73921 [CRITICAL] CWE-284 CVE-2026-73921: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon.
nvd
CVE-2026-73905P2CRITICALCVSS 9.8v4.5.02026-08-18
CVE-2026-73905 [CRITICAL] CWE-284 CVE-2026-73905: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. C
nvd
CVE-2026-73930P2CRITICALCVSS 9.9v4.5.32026-08-18
CVE-2026-73930 [CRITICAL] CWE-284 CVE-2026-73930: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.19 and 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significa
nvd
CVE-2026-73916P2CRITICALCVSS 9.1v3.2.182026-08-18
CVE-2026-73916 [CRITICAL] CWE-284 CVE-2026-73916: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation
nvd
CVE-2026-73917P2CRITICALCVSS 9.1v4.5.02026-08-18
CVE-2026-73917 [CRITICAL] CWE-284 CVE-2026-73917: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation,
nvd
CVE-2026-73866P2CRITICALCVSS 9.1v4.5.02026-08-18
CVE-2026-73866 [CRITICAL] CWE-284 CVE-2026-73866: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation,
nvd
CVE-2026-73922P2CRITICALCVSS 9.1v1.4.192026-08-18
CVE-2026-73922 [CRITICAL] CWE-284 CVE-2026-73922: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation
nvd
CVE-2026-73924P2CRITICALCVSS 9.1v1.4.192026-08-18
CVE-2026-73924 [CRITICAL] CWE-284 CVE-2026-73924: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation
nvd
CVE-2026-73865P2CRITICALCVSS 9.1v3.2.182026-08-18
CVE-2026-73865 [CRITICAL] CWE-284 CVE-2026-73865: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation
nvd
CVE-2026-71166P2CRITICALCVSS 9.4v3.2.182026-08-18
CVE-2026-71166 [CRITICAL] CWE-284 CVE-2026-71166: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation
nvd
CVE-2026-71167P2CRITICALCVSS 9.4v4.5.02026-08-18
CVE-2026-71167 [CRITICAL] CWE-284 CVE-2026-71167: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation,
nvd
CVE-2026-73920P2CRITICALCVSS 9.4v4.5.02026-08-18
CVE-2026-73920 [CRITICAL] CWE-284 CVE-2026-73920: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation,
nvd
CVE-2026-71065P2CRITICALCVSS 9.3v3.2.182026-08-18
CVE-2026-71065 [CRITICAL] CWE-284 CVE-2026-71065: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact addi
nvd
CVE-2026-73939P3HIGHCVSS 8.6v3.2.202026-08-18
CVE-2026-73939 [HIGH] CWE-284 CVE-2026-73939: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact addition
nvd
CVE-2026-71155P3HIGHCVSS 8.5v3.2.182026-08-18
CVE-2026-71155 [HIGH] CWE-284 CVE-2026-71155: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additiona
nvd
CVE-2026-71159P3HIGHCVSS 8.2v3.2.182026-08-18
CVE-2026-71159 [HIGH] CWE-284 CVE-2026-71159: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to cr
nvd
1 / 6Next →