Junglewise Threat Intelligence

CVE-2026-71158: Oracle Helidon unauthorized data access in Imperative Web Server

CVE-2026-71158 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a lightweight Java framework used to build microservices and cloud-native applications. An unauthenticated attacker can exploit this vulnerability over the network to gain unauthorized access to sensitive data stored in or accessible through Helidon-based applications without requiring any credentials or special privileges.

Technical details

This is an information disclosure vulnerability in the Imperative Web Server component of Oracle Helidon (versions 3.0.0 through 3.2.17). The vulnerability is easily exploitable and requires no authentication, user interaction, or special system configuration—only network access via HTTP. An unauthenticated remote attacker can exploit this flaw to read sensitive data or gain complete access to data accessible by the Helidon application. The vulnerability affects confidentiality but not integrity or availability. Patches are expected to be available through Oracle's security advisory channels.

Affected products

  • Oracle Helidon 3.0.0 through 3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats