{"cve":"CVE-2026-73923","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"1.4.20"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Helidon","source":"cna","vendor":"Oracle Corporation"},"product":"helidon","vendor":"oracle"}],"created":"2026-08-19T06:00:10.896477+00:00","title":"Helidon Imperative Web Server allows unauthenticated data modification via HTTP","updated":"2026-08-28T21:45:03.689464+00:00","vendors":["oracle","oracle$PRODUCT$helidon"]},"epss":{"score":0.00248},"mitre":{"cpes":["cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*"],"created":"2026-08-18T21:04:10.993000+00:00","description":"Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).  Supported versions that are affected are 1.0.0-1.4.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":3.7,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/73xxx/CVE-2026-73923.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-28T18:37:38.722000+00:00","vendors":["oracle","oracle$PRODUCT$helidon"],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:oracle:helidon:1.4.20:*:*:*:*:*:*:*"],"created":"2026-08-18T21:18:25.317000+00:00","description":"Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).  Supported versions that are affected are 1.0.0-1.4.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":3.7,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-73923.json","references":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"title":null,"updated":"2026-08-28T20:19:51.247000+00:00","vendors":["oracle","oracle$PRODUCT$helidon"],"weaknesses":["CWE-284"]},"opencve":{"changes":[{"created":"2026-08-18T21:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).   The supported version that is affected is 1.4.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$helidon"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:helidon:1.4.20:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$helidon"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":3.7,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"23ac3810-a1af-43fd-a4d2-dc66399bb376"},{"created":"2026-08-19T06:15:00+00:00","data":[{"details":{"new":"Integrity Violation in Oracle Helidon 1.4.20 Allows Unauthenticated Data Modification","old":null},"type":"title"},{"details":{"added":["CWE-732"],"removed":[]},"type":"weaknesses"}],"id":"ac78ed0b-151f-4a45-ba8b-d30c25270085"},{"created":"2026-08-19T15:30:00+00:00","data":[{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"},{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"59c8a24d-b133-49a8-8a39-10d9f91faee1"},{"created":"2026-08-19T17:15:00+00:00","data":[{"details":{"new":null,"old":"Integrity Violation in Oracle Helidon 1.4.20 Allows Unauthenticated Data Modification"},"type":"title"},{"details":{"added":[],"removed":["CWE-732"]},"type":"weaknesses"}],"id":"817c09db-26d8-4c94-bb15-767cf82c2b98"},{"created":"2026-08-19T20:30:00+00:00","data":[{"details":{"new":"Helidon Imperative Web Server Unauthorized Data Modification Vulnerability","old":null},"type":"title"}],"id":"c3df1869-2b6c-4489-aba6-09cc99f30aca"},{"created":"2026-08-20T03:30:00+00:00","data":[{"details":{"new":null,"old":"Helidon Imperative Web Server Unauthorized Data Modification Vulnerability"},"type":"title"}],"id":"57846223-2449-44c7-b090-feceaaf47fb0"},{"created":"2026-08-28T19:45:00+00:00","data":[{"details":{"new":"Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).  Supported versions that are affected are 1.0.0-1.4.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","old":"Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).   The supported version that is affected is 1.4.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)."},"type":"description"},{"details":{"added":["cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"}],"id":"f51ccdb2-026c-4665-9eb9-1169b92c1d1f"},{"created":"2026-08-28T22:00:00+00:00","data":[{"details":{"new":"Helidon Imperative Web Server allows unauthenticated data modification via HTTP","old":null},"type":"title"}],"id":"ebde788b-8d13-484e-85e4-a6826bbd4b93"}],"cpes":{"data":["cpe:2.3:a:oracle:helidon:*:*:*:*:*:*:*:*","cpe:2.3:a:oracle:helidon:1.4.20:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-08-18T21:04:10.993000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).  Supported versions that are affected are 1.0.0-1.4.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":3.7,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00248},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspuaug2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Helidon Imperative Web Server allows unauthenticated data modification via HTTP","provider":"enrichment"},"updated":{"data":"2026-08-28T21:45:03.689464+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$helidon"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-284"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-08-18T21:04:10.993000+00:00","description":"Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server).   The supported version that is affected is 1.4.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-08-19T14:01:29.350000+00:00","vendors":[],"vulnrichment_repo_path":"2026/73xxx/CVE-2026-73923.json","weaknesses":["CWE-284"]}}