Junglewise Threat Intelligence

CVE-2026-73872: Oracle Helidon information disclosure via HTTP

CVE-2026-73872 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a lightweight Java framework used to build web services and microservices within Oracle Fusion Middleware. An unauthenticated attacker on the network can exploit a vulnerability in the Imperative Web Server component to read sensitive data that Helidon can access, without requiring authentication or user interaction. This could expose configuration details, credentials, or other confidential information stored within or accessible by the application.

Technical details

This is an information disclosure vulnerability in the Helidon Imperative Web Server component affecting versions 4.0.0 through 4.4.1. The vulnerability is easily exploitable and requires only network access via HTTP; no authentication or user interaction is required. An unauthenticated attacker can trigger unauthorized read access to a subset of Helidon-accessible data. The root cause appears to be inadequate access controls or input validation in the HTTP request handling path. Patch availability has not been explicitly confirmed in the provided advisory materials.

Affected products

  • Oracle Helidon 4.0.0–4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats