Executive brief
Helidon is a lightweight framework used to build web services and microservices. A critical remote code execution vulnerability in the Imperative Web Server component allows unauthenticated attackers to completely compromise affected systems over the network without authentication, potentially leading to full takeover of the application and data exposure.
Technical details
The vulnerability is a remote code execution flaw in the Helidon Imperative Web Server component affecting versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1. It requires only network access via HTTP and can be exploited without authentication or user interaction. The attack vector is network-based with low complexity, allowing an unauthenticated attacker to achieve complete compromise of confidentiality, integrity, and availability. Patch availability has not been confirmed in the provided advisory.
Affected products
- Oracle Helidon 3.0.0-3.2.17, 4.0.0-4.4.1
Timeline
- 2026-08-18: disclosed