Junglewise Threat Intelligence

CVE-2026-71156: Oracle Helidon data integrity vulnerability

CVE-2026-71156 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a web server component used in Oracle Fusion Middleware to handle HTTP requests. An unauthenticated remote attacker can exploit this vulnerability via the network to modify, insert, or delete data that Helidon can access, compromising data integrity without requiring authentication or user interaction.

Technical details

This vulnerability exists in the Imperative Web Server component of Oracle Helidon (versions 3.0.0–3.2.18). The vulnerability allows an unauthenticated attacker with network access to exploit an HTTP-based flaw to perform unauthorized modifications to data accessible by Helidon. No authentication, elevated privileges, or user interaction is required; exploitation is straightforward due to low attack complexity. Successful exploitation results in integrity compromise (unauthorized update, insert, or delete operations) with no impact on confidentiality or availability. A patch should be available through Oracle's standard security patch process.

Affected products

  • Oracle Helidon 3.0.0 through 3.2.18

Timeline

  • 2026-08-18: disclosed

References

Related threats