Junglewise Threat Intelligence

CVE-2026-73868: Oracle Helidon unauthorized data access vulnerability

CVE-2026-73868 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is an open-source framework for building microservices and web applications that is part of Oracle Fusion Middleware. This vulnerability allows an unauthenticated attacker to access Helidon over the network and gain unauthorized read access to sensitive data, as well as perform unauthorized modifications (create, update, or delete) to certain data stored in Helidon. Exploitation requires no special privileges and could lead to data breaches or data integrity issues in applications built with affected versions.

Technical details

The vulnerability exists in the Imperative Web Server component of Oracle Helidon and affects versions 4.0.0 through 4.4.1. It is an easily exploitable authorization flaw that allows unauthenticated attackers with network access via HTTP to compromise the application. The vulnerability permits unauthorized read access to a subset of accessible data and unauthorized update/insert/delete operations on some Helidon-accessible data. No user interaction or authentication is required; an attacker can trigger the issue remotely over the network. Patches are expected from Oracle to remediate the affected versions.

Affected products

  • Oracle Helidon 4.0.0-4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats