Oracle Helidon vulnerabilities
104 known vulnerabilities affecting oracle/helidon.
Total CVEs
104
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH41MEDIUM44LOW2
Vulnerabilities
Page 5 of 6
CVE-2026-73889P4MEDIUMCVSS 5.3v4.5.02026-08-18
CVE-2026-73889 [MEDIUM] CWE-284 CVE-2026-73889: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access
nvd
CVE-2026-73898P4MEDIUMCVSS 6.1v4.5.02026-08-18
CVE-2026-73898 [MEDIUM] CWE-284 CVE-2026-73898: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attac
nvd
CVE-2026-70923P4MEDIUMCVSS 6.1v3.2.192026-08-18
CVE-2026-70923 [MEDIUM] CWE-285 CVE-2026-70923: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the atta
nvd
CVE-2026-73869P4MEDIUMCVSS 6.1v3.2.182026-08-18
CVE-2026-73869 [MEDIUM] CWE-284 CVE-2026-73869: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the atta
nvd
CVE-2026-73870P4MEDIUMCVSS 6.1v4.5.02026-08-18
CVE-2026-73870 [MEDIUM] CWE-284 CVE-2026-73870: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks require human interaction from a person other than the attac
nvd
CVE-2026-71154P4MEDIUMCVSS 6.1v4.5.02026-08-18
CVE-2026-71154 [MEDIUM] CWE-284 CVE-2026-71154: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Helidon executes to compromise Helidon. Successful attacks of this vulnerability can result i
nvd
CVE-2026-71165P4MEDIUMCVSS 5.4v3.2.182026-08-18
CVE-2026-71165 [MEDIUM] CWE-284 CVE-2026-71165: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, ins
nvd
CVE-2026-73881P4MEDIUMCVSS 5.4v4.5.02026-08-18
CVE-2026-73881 [MEDIUM] CWE-284 CVE-2026-73881: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, inse
nvd
CVE-2026-73913P4MEDIUMCVSS 5.4v4.5.02026-08-18
CVE-2026-73913 [MEDIUM] CWE-284 CVE-2026-73913: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, inse
nvd
CVE-2026-73919P4MEDIUMCVSS 5.4v3.2.182026-08-18
CVE-2026-73919 [MEDIUM] CWE-284 CVE-2026-73919: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, ins
nvd
CVE-2026-73911P4MEDIUMCVSS 5.4v4.5.02026-08-18
CVE-2026-73911 [MEDIUM] CWE-284 CVE-2026-73911: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, inse
nvd
CVE-2026-73874P4MEDIUMCVSS 5.4v4.5.02026-08-18
CVE-2026-73874 [MEDIUM] CWE-284 CVE-2026-73874: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, inse
nvd
CVE-2026-73872P4MEDIUMCVSS 5.3v4.5.02026-08-18
CVE-2026-73872 [MEDIUM] CWE-284 CVE-2026-73872: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access
nvd
CVE-2026-73910P4MEDIUMCVSS 5.3v4.5.12026-08-18
CVE-2026-73910 [MEDIUM] CWE-284 CVE-2026-73910: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access
nvd
CVE-2026-73871P4MEDIUMCVSS 5.3v3.2.182026-08-18
CVE-2026-73871 [MEDIUM] CWE-284 CVE-2026-73871: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read acces
nvd
CVE-2026-73900P4MEDIUMCVSS 5.3v4.5.12026-08-18
CVE-2026-73900 [MEDIUM] CWE-284 CVE-2026-73900: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access
nvd
CVE-2026-71156P4MEDIUMCVSS 5.3v3.2.192026-08-18
CVE-2026-71156 [MEDIUM] CWE-284 CVE-2026-71156: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, in
nvd
CVE-2026-71161P4MEDIUMCVSS 5.3v3.2.182026-08-18
CVE-2026-71161 [MEDIUM] CWE-284 CVE-2026-71161: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 3.0.0-3.2.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2026-73932P4MEDIUMCVSS 5.3v4.5.32026-08-18
CVE-2026-73932 [MEDIUM] CWE-284 CVE-2026-73932: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2026-73901P4MEDIUMCVSS 4.8v4.5.12026-08-18
CVE-2026-73901 [MEDIUM] CWE-284 CVE-2026-73901: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions that are affected are 4.0.0-4.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized update, i
nvd