Executive brief
Helidon is an open-source Java framework used to build microservices and web applications. An unauthenticated attacker can exploit this vulnerability over the network to read sensitive data or modify data within Helidon-based applications without proper authorization, potentially compromising business-critical systems and customer information.
Technical details
This is a network-accessible authentication bypass vulnerability in Helidon's Imperative Web Server component (versions 3.0.0 through 3.2.17). The vulnerability allows unauthenticated attackers to bypass security controls via HTTP requests, requiring no special privileges or user interaction. Successful exploitation results in unauthorized read access to critical data and unauthorized modification (insert, update, delete) of some accessible data. The exact root cause is not disclosed, but the attack vector is HTTP-based and easily exploitable. Patches are expected to be available from Oracle through standard security updates.
Affected products
- Oracle Helidon 3.0.0 through 3.2.17
Timeline
- 2026-08-18: disclosed