Executive brief
Oracle Helidon is a lightweight Java-based web server component used in Oracle Fusion Middleware environments to handle HTTP requests and serve web applications. A vulnerability in versions 3.0.0 through 3.2.17 allows low-privileged attackers with network access to read sensitive data and make unauthorized modifications to records, potentially compromising customer data and system integrity across dependent applications.
Technical details
This vulnerability in the Helidon Imperative Web Server allows an authenticated attacker with low privileges to exploit a flaw via HTTP requests without user interaction. The attack has network reachability and requires valid credentials but low privilege level. Successful exploitation results in unauthorized read access to critical data and limited write/modify access to application data within Helidon's scope, with potential scope change affecting downstream systems. The vulnerability affects versions 3.0.0 through 3.2.17, and patches are expected from Oracle's security advisory (though access details were unavailable at time of analysis).
Affected products
- Oracle Helidon 3.0.0 through 3.2.17
Timeline
- 2026-08-18: disclosed