Executive brief
Oracle Helidon is a web server framework used to build cloud-native applications as part of Oracle Fusion Middleware. An unauthenticated attacker can exploit this vulnerability over HTTP to read, modify, or delete sensitive data stored in affected applications—without requiring user interaction or special network positioning.
Technical details
This vulnerability in Oracle Helidon's Imperative Web Server component allows an unauthenticated, network-accessible attacker to bypass authorization controls via HTTP requests. The flaw permits unauthorized read, update, insert, and delete operations on a subset of accessible data. Versions 3.0.0 through 3.2.17 are affected. The attack requires no authentication, no special privileges, and no user interaction. Patches are available via Oracle's critical patch updates.
Affected products
- Oracle Helidon 3.0.0-3.2.17
Timeline
- 2026-08-18: disclosed