Executive brief
Oracle Helidon is a lightweight Java framework used to build web applications and microservices. A vulnerability in its Imperative Web Server component allows a low-privileged attacker with network access to read, modify, or delete data handled by the application, compromising data confidentiality and integrity. This affects organizations relying on Helidon for mission-critical web services.
Technical details
A data access control vulnerability exists in the Imperative Web Server component of Oracle Helidon versions 3.0.0 through 3.2.17. The vulnerability requires network access via HTTP and low-level privileges, with difficult exploitability characteristics. Successful exploitation permits unauthorized read access to a subset of Helidon-accessible data and unauthorized update, insert, or delete operations on some data. The attack vector is network-based, does not require user interaction, and does not affect availability. No patch or fix availability information is currently disclosed.
Affected products
- Oracle Helidon 3.0.0-3.2.17
Timeline
- 2026-08-18: disclosed