Executive brief
Oracle Helidon is a lightweight Java framework used to build microservices and web applications. This vulnerability in its Imperative Web Server component allows an attacker to trick a user into performing unauthorized actions, such as modifying or deleting data. The flaw requires user interaction and could affect data integrity and confidentiality of applications built on affected Helidon versions.
Technical details
This is a cross-site request forgery (CSRF) vulnerability in Oracle Helidon's Imperative Web Server component affecting versions 3.0.0 through 3.2.17. The vulnerability is exploitable over the network via HTTP without requiring authentication, but successful exploitation depends on a user's action (e.g., following a malicious link). While the flaw exists in Helidon, attacks may impact dependent applications that integrate this component. An attacker can achieve unauthorized read access to sensitive data and unauthorized modification (update/insert/delete) of Helidon-accessible data. Patches are expected to be available through Oracle's security updates.
Affected products
- Oracle Helidon 3.0.0 through 3.2.17
Timeline
- 2026-08-18: disclosed