Junglewise Threat Intelligence

CVE-2026-71167: Oracle Helidon unauthenticated data access and denial of service

CVE-2026-71167 · Severity: critical · CVSS 9.4 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is an open-source microservices framework used to build cloud-native applications. A critical vulnerability in the Imperative Web Server component allows unauthenticated attackers on the network to read, modify, or delete sensitive data and cause service disruptions without any credentials or user interaction. Organizations using affected Helidon versions face immediate risk of data breach and operational downtime.

Technical details

This is an unauthenticated remote vulnerability in the Helidon Imperative Web Server component affecting versions 4.0.0 through 4.4.1. The vulnerability can be exploited via HTTP by a network-based attacker without requiring authentication, elevated privileges, or user interaction. Successful exploitation results in unauthorized read, creation, modification, and deletion of critical data accessible to Helidon, as well as the ability to trigger partial denial of service conditions. The CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L) reflects the high impact across confidentiality, integrity, and availability. Patches are expected from Oracle; affected systems should update to versions beyond 4.4.1 when available.

Affected products

  • Oracle Helidon 4.0.0-4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats