CVE-2026-73900
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affecte
CVSS
5.3
Medio
EPSS
0.2%
p15
KEV
—
Exploit Today
4
0-100
Publicado: 18 ago 2026 · Última mod.: 21 ago 2026 · CWE-284
0.2%EPSS · 30 días0.2%
2026-08-192026-08-26
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-614197.8 ALT0.7%
——0Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.3dCVE-2026-782457.3 ALT39.0%
——12A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.3dCVE-2026-782027.3 ALT20.8%
——6A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.3dCVE-2026-76609—14.8%
——4Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.3dCVE-2026-76608—21.6%
——6Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access checks.3dCVE-2026-76607—14.8%
——4Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.3d