Junglewise Threat Intelligence

CVE-2026-70923: Oracle Helidon security bypass via HTTP request

CVE-2026-70923 · Severity: medium · CVSS 6.1 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is Oracle's lightweight Java-based web server framework used to build cloud-native applications. An unauthenticated attacker can exploit a flaw over HTTP to read, modify, or delete sensitive data accessible to the Helidon application, though exploitation requires tricking a legitimate user into performing an action (such as clicking a malicious link). The vulnerability affects a wide version range and could have broader impact on dependent systems.

Technical details

This vulnerability in Oracle Helidon's Imperative Web Server component is easily exploitable without authentication via HTTP. It allows an unauthenticated, network-accessible attacker to compromise affected systems; however, successful exploitation requires user interaction (e.g., social engineering or clickjacking). The vulnerability has scope change, meaning attacks against Helidon can significantly impact other products that depend on it. Successful exploitation results in unauthorized read access to a subset of Helidon data and unauthorized update, insert, or delete operations on some data. The vulnerability affects versions 3.0.0 through 3.2.18. Patch availability information is not detailed in the advisory.

Affected products

  • Oracle Helidon 3.0.0 through 3.2.18

Timeline

  • 2026-08-18: disclosed

References

Related threats