Junglewise Threat Intelligence

CVE-2026-71165: Oracle Helidon unauthorized data access in Imperative Web Server

CVE-2026-71165 · Severity: medium · CVSS 5.4 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a web server component used in Oracle Fusion Middleware to handle HTTP requests and serve web applications. A vulnerability in the Imperative Web Server allows low-privileged attackers with network access to read sensitive data and make unauthorized modifications to application data. Exploiting this flaw could lead to data breaches and unauthorized changes to business-critical information.

Technical details

The vulnerability is an authorization bypass flaw in the Helidon Imperative Web Server that permits authenticated but low-privileged attackers to access and modify data they should not be able to. The vulnerability is reachable via HTTP from the network and requires valid credentials (low privilege level). Successful exploitation results in confidentiality impact (unauthorized read access to a subset of accessible data) and integrity impact (unauthorized update, insert, or delete operations). The flaw affects versions 3.0.0 through 3.2.17; patches are expected from Oracle.

Affected products

  • Oracle Helidon 3.0.0-3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats