Junglewise Threat Intelligence

CVE-2026-73873: Oracle Helidon data access vulnerability in Imperative Web Server

CVE-2026-73873 · Severity: medium · CVSS 4.2 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework used to build web applications and microservices. A vulnerability in its Imperative Web Server component allows a low-privileged attacker with network access to read, modify, or delete data handled by the application, compromising data confidentiality and integrity. This affects organizations relying on Helidon for mission-critical web services.

Technical details

A data access control vulnerability exists in the Imperative Web Server component of Oracle Helidon versions 3.0.0 through 3.2.17. The vulnerability requires network access via HTTP and low-level privileges, with difficult exploitability characteristics. Successful exploitation permits unauthorized read access to a subset of Helidon-accessible data and unauthorized update, insert, or delete operations on some data. The attack vector is network-based, does not require user interaction, and does not affect availability. No patch or fix availability information is currently disclosed.

Affected products

  • Oracle Helidon 3.0.0-3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats