Junglewise Threat Intelligence

CVE-2026-71157: Oracle Helidon information disclosure in Imperative Web Server

CVE-2026-71157 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework used to build cloud-native microservices and web applications. A vulnerability in the Imperative Web Server component allows unauthenticated attackers to read sensitive data without authorization. An attacker with network access can exploit this flaw remotely via HTTP to gain unauthorized access to a subset of application data, potentially exposing configuration, credentials, or business-critical information.

Technical details

This is an information disclosure vulnerability in the Helidon Imperative Web Server component. The vulnerability is easily exploitable and requires no authentication or user interaction—an attacker with network access can send a crafted HTTP request to trigger unauthorized read access. The flaw affects Helidon versions 3.0.0 through 3.2.17 and 4.0.0 through 4.4.1. The attack vector is network-based and results in confidentiality impact (unauthorized data access) without affecting integrity or availability. Oracle has issued a security patch; users should upgrade to patched versions.

Affected products

  • Oracle Helidon 3.0.0-3.2.17, 4.0.0-4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats