Executive brief
Helidon is Oracle's web server component used to build microservices and cloud-native applications. An unauthenticated attacker can exploit this critical vulnerability over the network to read, modify, or delete sensitive data without any authorization or user interaction. The vulnerability exposes all data accessible by Helidon and could impact application availability and data integrity.
Technical details
This is an easily exploitable vulnerability in Helidon versions 3.0.0 through 3.2.17 that allows unauthenticated, network-based attacks via HTTP. The vulnerability is in the Imperative Web Server component and enables attackers to achieve both confidentiality and integrity impacts, permitting unauthorized creation, deletion, and modification of critical data. No user interaction is required for exploitation, and the attack has a low complexity threshold. Patch updates are expected to be available through Oracle's security advisory channel.
Affected products
- Oracle Helidon 3.0.0-3.2.17
Timeline
- 2026-08-18: disclosed