Junglewise Threat Intelligence

CVE-2026-73870: Oracle Helidon privilege escalation in Imperative Web Server

CVE-2026-73870 · Severity: medium · CVSS 6.1 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a framework for building microservices and web applications used in enterprise environments. This vulnerability in the Imperative Web Server component allows unauthenticated attackers to compromise the system over HTTP with user interaction, potentially exposing or modifying sensitive application data. The attack can also impact other products that depend on Helidon.

Technical details

This is an easily exploitable vulnerability in Oracle Helidon's Imperative Web Server (versions 4.0.0–4.4.1) that can be exploited via HTTP by an unauthenticated network attacker. The vulnerability requires user interaction and can lead to unauthorized read and write access to some data handled by Helidon, with scope change indicating potential impact on connected systems. The root cause and specific attack vector are not detailed in the advisory, but the low complexity and network accessibility suggest a client-side or request-handling flaw. Patches are expected from Oracle as part of their security update cycle.

Affected products

  • Oracle Helidon 4.0.0–4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats