Unauthenticated Access Vulnerability in Helidon by Oracle Fusion Middleware
CVE-2026-83278

6.8MEDIUM

Key Information:

Vendor

Oracle

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-83278?

The Helidon product of Oracle Fusion Middleware is affected by a vulnerability that allows an unauthenticated attacker, with physical access to the communication segment of the hardware, to compromise the Helidon environment. Exploiting this vulnerability can lead to unauthorized creation, deletion, or modification of critical data, granting complete access to all data accessible by Helidon. This poses significant confidentiality and integrity risks to affected systems.

Affected Version(s)

Helidon 3.0.0 <= 3.2.20

Helidon 4.0.0 <= 4.5.4

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.