Executive brief
Oracle Helidon is a lightweight Java web framework used to build cloud-native applications and microservices. A vulnerability in its HTTP request handling allows unauthenticated remote attackers to access sensitive data and modify application data without proper authorization. This could lead to unauthorized exposure of customer information or manipulation of critical business data.
Technical details
A difficult-to-exploit authorization bypass vulnerability exists in Oracle Helidon's Imperative Web Server component, affecting versions 3.0.0 through 3.2.17. The vulnerability allows an unauthenticated attacker to send specially crafted HTTP requests that bypass access controls, resulting in unauthorized read access to sensitive data and limited write/delete access to protected resources. No user interaction or authentication is required; the attack is network-accessible but has high complexity (AC:H). The vulnerability enables attackers to read confidential data and perform unauthorized modifications with high and low severity impact respectively, according to CVSS scoring.
Affected products
- Oracle Helidon 3.0.0 to 3.2.17
Timeline
- 2026-08-18: disclosed
- other: CVE-2026-71162