Junglewise Threat Intelligence

CVE-2026-71154: Oracle Helidon privilege escalation in Imperative Web Server

CVE-2026-71154 · Severity: medium · CVSS 6.1 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight web server framework used in Oracle Fusion Middleware environments. The vulnerability allows a low-privileged user with local access to the server to gain unauthorized access to sensitive data or modify stored information. This could expose business-critical data or allow unauthorized changes to application configurations and databases.

Technical details

This is a local privilege escalation vulnerability in the Imperative Web Server component of Helidon (versions 4.0.0–4.4.1). The vulnerability requires local system access and low privileges; no network exposure or user interaction is needed. An attacker with logon access to the infrastructure can exploit the flaw to read sensitive data (high confidentiality impact) and perform unauthorized updates or inserts on accessible data (limited integrity impact). The CVSS 3.1 score of 6.1 reflects local attack vector, low privileges required, and partial data modification scope.

Affected products

  • Oracle Helidon 4.0.0-4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats