
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-73939 is an Improper Access Control vulnerability in the Imperative Web Server component of Oracle Helidon, part of Oracle Fusion Middleware. It affects version 3.2.20 and allows unauthenticated remote attackers to tamper with critical data via HTTP. The vulnerability was disclosed on August 18, 2026, as part of Oracle's August 2026 Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 8.6 (High), with a scope change indicating potential impact beyond the directly affected component (Oracle CSPU Aug 2026, Github Advisory).
The vulnerability is classified as CWE-284 (Improper Access Control), meaning the Helidon Imperative Web Server component fails to properly restrict access to resources from unauthorized actors (Github Advisory). An unauthenticated attacker with network access can send crafted HTTP requests to exploit this flaw — no privileges or user interaction are required, and attack complexity is low. The scope change (S:C) in the CVSS vector indicates that a successful attack can affect resources or components beyond the Helidon instance itself, potentially impacting other products in the same environment (Oracle CSPU Aug 2026). No public proof-of-concept or detailed technical write-up has been identified at this time.
Successful exploitation allows an unauthenticated attacker to perform unauthorized creation, deletion, or modification of critical data accessible by Helidon, resulting in a high integrity impact with no confidentiality or availability impact (Oracle CSPU Aug 2026). The scope change means attacks may significantly affect additional products beyond Helidon itself, increasing the potential blast radius in environments where Helidon is integrated with other Oracle Fusion Middleware components. Data integrity loss could include manipulation of application data, configuration tampering, or injection of malicious content into downstream systems.
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been observed as of the time of disclosure (Github Advisory). CISA's SSVC assessment classifies the vulnerability as "automatable: yes" and "exploitation: none," indicating it could be exploited at scale but has not been actively weaponized (Oracle CSPU Aug 2026). The EPSS score is approximately 0.34%, placing it in the 26th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Oracle has released a patch for this vulnerability as part of the August 2026 Critical Security Patch Update; affected users running Helidon 3.2.20 should apply the patch immediately (Oracle CSPU Aug 2026). As a temporary workaround, Oracle recommends blocking network protocols required by the attack (i.e., restricting HTTP access to Helidon to trusted sources only) until patching can be completed, though this may impact application functionality. Deploying a Web Application Firewall (WAF) to filter anomalous HTTP requests targeting Helidon endpoints is also recommended as a defense-in-depth measure while coordinating patch deployment across affected systems.
The vulnerability received coverage from The Hacker Wire shortly after disclosure, with a dedicated article on the unauthenticated data tampering issue in Helidon's Imperative Web Server (The Hacker Wire). The vulnerability was also noted on Mastodon via The Hacker Wire's social account. No significant broader community debate or notable researcher commentary beyond initial disclosure coverage has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."