Unauthenticated Access Vulnerability in Oracle Helidon Web Server
CVE-2026-73923

3.7LOW

Key Information:

Vendor

Oracle

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-73923?

A vulnerability exists in Oracle Helidon's Imperative Web Server, where an unauthenticated attacker with network access via HTTP can exploit it. This weakness allows potential unauthorized alteration of data, including updates, inserts, or deletions. The affected version is 1.4.20, and it poses a significant risk to the integrity of the data accessible through Helidon.

Affected Version(s)

Helidon 1.4.20

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.