Junglewise Threat Intelligence

CVE-2026-71110: Oracle Helidon unauthorized data access vulnerability

CVE-2026-71110 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a lightweight web server framework used to build cloud-native applications as part of Oracle Fusion Middleware. A vulnerability in the Imperative Web Server component allows a low-privileged attacker with network access to read, modify, or delete critical data without authorization, potentially exposing sensitive application information or corrupting business-critical databases.

Technical details

The vulnerability exists in the Imperative Web Server component of Helidon and is easily exploitable via HTTPS by an authenticated attacker with low privileges. The attack requires network access but no user interaction. Successful exploitation allows an attacker to gain unauthorized read, write, and delete access to Helidon-accessible data, compromising both confidentiality and integrity. The issue affects versions 1.0.0–1.4.18, 3.0.0–3.2.17, and 4.0.0–4.4.1. Patches are expected to be available through Oracle's standard security update channels.

Affected products

  • Oracle Helidon 1.0.0–1.4.18, 3.0.0–3.2.17, 4.0.0–4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats