
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73937 is a vulnerability in the Helidon product of Oracle Fusion Middleware, specifically affecting the Imperative Web Server component. It allows unauthenticated remote attackers to exploit the system via the HTTP/2 protocol, resulting in denial of service and partial information disclosure. Only version 4.5.0 of Oracle Helidon is confirmed affected. The vulnerability was disclosed on August 18, 2026, as part of Oracle's Critical Security Patch Update (CSPU) for August 2026, and carries a CVSS v3.1 base score of 8.2 (High) (Oracle Advisory, Github Advisory).
The vulnerability is classified under CWE-284 (Improper Access Control), indicating that the Helidon Imperative Web Server fails to properly restrict access to resources when processing HTTP/2 requests (Github Advisory). An unauthenticated attacker with network access can send crafted HTTP/2 requests to trigger a hang or crash of the Helidon service, and may also gain unauthorized read access to a subset of data accessible by the server. No authentication, user interaction, or elevated privileges are required, and attack complexity is low, making this easily exploitable from the network. No detailed technical write-ups or public proof-of-concept code have been identified at this time (Oracle Advisory).
Successful exploitation results in a complete denial of service — the Helidon server can be caused to hang or crash repeatedly — as well as unauthorized read access to a subset of data accessible by the Helidon instance. The availability impact is rated High and the confidentiality impact is rated Low, with no integrity impact. Because the attack requires no authentication and is network-accessible, any internet-facing Helidon 4.5.0 deployment is at risk of service disruption and potential data exposure (Oracle Advisory, Github Advisory).
As of the time of disclosure, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (Github Advisory). CISA's SSVC assessment classifies the vulnerability as "automatable: yes" and "exploitation: none," indicating that while the attack can be automated, no exploitation has been observed (Oracle Advisory). The EPSS score is approximately 0.39%, placing it in the 32nd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Oracle has released a patch for this vulnerability as part of the August 2026 Critical Security Patch Update; users should upgrade Oracle Helidon from version 4.5.0 to a patched version as soon as possible (Oracle Advisory). As interim mitigations, restrict network access to the Helidon HTTP/2 service to trusted clients only, implement rate limiting and connection throttling to reduce denial-of-service impact, and monitor for unexpected crashes or hangs of Helidon services. Oracle strongly recommends applying security patches without delay rather than relying on network-level workarounds as a long-term solution.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."