Executive brief
Oracle Helidon is a web server framework used as part of Oracle Fusion Middleware to build and run enterprise applications. An unauthenticated attacker with network access can exploit this vulnerability to read sensitive data that Helidon is protecting, without needing to authenticate or perform any special user interaction.
Technical details
This is an unauthorized information disclosure vulnerability in the Helidon Imperative Web Server component affecting versions 3.0.0 through 3.2.17. The vulnerability is easily exploitable over HTTPS without authentication (network-accessible, no login required, no user interaction needed). An attacker can achieve unauthorized read access to a subset of Helidon-accessible data through a direct network request. Patches are expected from Oracle; users should apply security updates when released.
Affected products
- Oracle Helidon 3.0.0-3.2.17
Timeline
- 2026-08-18: disclosed