cbcvebase.

Oracle Helidon vulnerabilities

104 known vulnerabilities affecting oracle/helidon.

Total CVEs
104
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH41MEDIUM44LOW2

Vulnerabilities

Page 2 of 6
CVE-2026-71110P3HIGHCVSS 8.1v4.5.02026-08-18
CVE-2026-71110 [HIGH] CWE-269 CVE-2026-71110: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18, 3.0.0-3.2.17 and 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Helidon. Successful attacks of this vulnerability can resul
nvd
CVE-2022-21404P3HIGHCVSS 8.1v1.4.10v2.0.02022-04-19
CVE-2022-21404 [HIGH] CVE-2022-21404: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer). Su Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer). Supported versions that are affected are 1.4.10 and 2.0.0-RC1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS
nvd
CVE-2026-73925P3HIGHCVSS 8.2v1.4.192026-08-18
CVE-2026-73925 [HIGH] CWE-284 CVE-2026-73925: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, de
nvd
CVE-2026-73929P3HIGHCVSS 8.3v4.5.32026-08-18
CVE-2026-73929 [HIGH] CWE-284 CVE-2026-73929: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additiona
nvd
CVE-2026-73937P3HIGHCVSS 8.2v4.5.02026-08-18
CVE-2026-73937 [HIGH] CWE-284 CVE-2026-73937: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2026-73884P3HIGHCVSS 7.5v4.5.02026-08-18
CVE-2026-73884 [HIGH] CWE-200 CVE-2026-73884: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to cri
nvd
CVE-2026-73878P3HIGHCVSS 7.5v3.2.182026-08-18
CVE-2026-73878 [HIGH] CWE-200 CVE-2026-73878: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to cr
nvd
CVE-2026-73883P3HIGHCVSS 7.5v3.2.182026-08-18
CVE-2026-73883 [HIGH] CWE-200 CVE-2026-73883: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to cr
nvd
CVE-2026-73938P3HIGHCVSS 7.5v4.5.02026-08-18
CVE-2026-73938 [HIGH] CWE-284 CVE-2026-73938: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to cri
nvd
CVE-2026-73907P3HIGHCVSS 7.5v3.2.182026-08-18
CVE-2026-73907 [HIGH] CWE-284 CVE-2026-73907: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to cr
nvd
CVE-2026-71158P3HIGHCVSS 7.5v3.2.182026-08-18
CVE-2026-71158 [HIGH] CWE-284 CVE-2026-71158: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to cr
nvd
CVE-2026-73879P3HIGHCVSS 7.5v4.5.12026-08-18
CVE-2026-73879 [HIGH] CWE-284 CVE-2026-73879: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, del
nvd
CVE-2026-73903P3HIGHCVSS 7.5v4.5.12026-08-18
CVE-2026-73903 [HIGH] CWE-284 CVE-2026-73903: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, del
nvd
CVE-2026-71160P3HIGHCVSS 7.5v3.2.182026-08-18
CVE-2026-71160 [HIGH] CWE-284 CVE-2026-71160: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 1.0.0-1.4.18 and 3.0.0-3.2.17. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeove
nvd
CVE-2026-73887P3HIGHCVSS 7.5v4.5.02026-08-18
CVE-2026-73887 [HIGH] CWE-284 CVE-2026-73887: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to c
nvd
CVE-2026-73908P3HIGHCVSS 7.5v4.5.02026-08-18
CVE-2026-73908 [HIGH] CWE-284 CVE-2026-73908: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized access to cri
nvd
CVE-2026-60915P3HIGHCVSS 7.4v4.5.02026-08-18
CVE-2026-60915 [HIGH] CWE-284 CVE-2026-60915: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17 and 4.0.0-4.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2026-73931P3HIGHCVSS 8.3v4.5.32026-08-18
CVE-2026-73931 [HIGH] CWE-284 CVE-2026-73931: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additiona
nvd
CVE-2026-73918P3HIGHCVSS 7.3v4.5.02026-08-18
CVE-2026-73918 [HIGH] CWE-284 CVE-2026-73918: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, inser
nvd
CVE-2026-73894P3HIGHCVSS 7.3v4.5.02026-08-18
CVE-2026-73894 [HIGH] CWE-284 CVE-2026-73894: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, inser
nvd
Oracle Helidon vulnerabilities | cvebase