Junglewise Threat Intelligence

CVE-2026-71166: Oracle Helidon remote code execution in Imperative Web Server

CVE-2026-71166 · Severity: critical · CVSS 9.4 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is an open-source Java framework used to build microservices and web applications, typically deployed in enterprise environments. A critical vulnerability in its Imperative Web Server component allows unauthenticated attackers on the network to execute unauthorized operations on the server, including modification or deletion of sensitive data, complete data exfiltration, and partial service disruptions—all without credentials or user interaction required.

Technical details

An easily exploitable vulnerability in the Helidon Imperative Web Server component (versions 3.0.0 through 3.2.17) allows unauthenticated network-based attackers to gain unauthorized access and control via HTTP. The vulnerability has a network attack vector with no authentication required and no user interaction needed. Successful exploitation results in unauthorized creation, deletion, or modification of critical data, complete confidentiality compromise of Helidon-accessible data, and partial denial of service. The CVSS 3.1 score of 9.4 reflects high impacts across confidentiality, integrity, and availability (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).

Affected products

  • Oracle Helidon 3.0.0 through 3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats