Junglewise Threat Intelligence

CVE-2026-73867: Oracle Helidon unauthorized data access vulnerability

CVE-2026-73867 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a web server framework used to build cloud-native applications as part of Oracle Fusion Middleware. An unauthenticated attacker can exploit this vulnerability over HTTP to read, modify, or delete sensitive data stored in affected applications—without requiring user interaction or special network positioning.

Technical details

This vulnerability in Oracle Helidon's Imperative Web Server component allows an unauthenticated, network-accessible attacker to bypass authorization controls via HTTP requests. The flaw permits unauthorized read, update, insert, and delete operations on a subset of accessible data. Versions 3.0.0 through 3.2.17 are affected. The attack requires no authentication, no special privileges, and no user interaction. Patches are available via Oracle's critical patch updates.

Affected products

  • Oracle Helidon 3.0.0-3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats