Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-73930 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-08-18 |
| Vendor | Oracle |
| Product | Helidon (Fusion Middleware) |
| CVSS Score | 9.9 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. While the vulnerability is in Helidon, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critica…
Required Actions
- Apply the fixes from the Oracle Critical Patch Update of August 2026 (cspuaug2026). This is the only official patch source for the entire group.
- Plan one update, not ten tasks. All ten CVEs affect the same component (Imperative Web Server) and are closed by the same bulletin. Splitting the work per CVE only extends the exposure window.
- Determine which Helidon lines are in use — the bulletin covers three at once: 1.4.19 and 1.4.20, 3.2.18, and 4.5.0 and 4.5.3. Updating one branch does not close the others.
- Find affected instances by analyzing build dependencies rather than server inventory. Helidon is a framework embedded in the application, so it will not appear in installed-software lists.
- Note the scope change in CVE-2026-73930 (CVSS 9.9): a successful attack does not necessarily stop at Helidon itself. Assess which components run in the same trust context.
Who Is Affected?
Organizations running Java applications on the Oracle Helidon framework, lines 1.x, 3.x or 4.x. Because Helidon is embedded in the application rather than installed as a separate server, affected instances are most easily found by analyzing development teams’ build dependencies.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
