Executive brief
Helidon is a web server framework used within Oracle Fusion Middleware to power application services. An unauthenticated attacker can exploit this vulnerability over the network to read, modify, or delete critical application data without needing valid credentials. This poses a severe risk to confidentiality and integrity of systems running affected Helidon versions.
Technical details
The vulnerability in Helidon's Imperative Web Server (versions 4.0.0–4.4.1) can be exploited by an unauthenticated, network-based attacker via HTTP without requiring user interaction or special configuration. The flaw allows unauthorized read and write access to sensitive data handled by the web server. No patch availability details are currently available in the advisory text, but given the critical CVSS score of 9.1 and the recent publication date, patches may be under development or imminent.
Affected products
- Oracle Helidon 4.0.0 through 4.4.1
Timeline
- 2026-08-18: disclosed