Executive brief
Oracle Helidon is a lightweight web server framework used to build microservices within Oracle Fusion Middleware environments. A vulnerability in the Imperative Web Server component allows a low-privileged attacker to read sensitive data and modify or delete records through HTTP requests, potentially compromising business-critical applications and exposing confidential information.
Technical details
The vulnerability exists in the Imperative Web Server component of Oracle Helidon versions 4.0.0 through 4.4.1. It allows a low-privileged, authenticated attacker with network access to perform unauthorized read, update, insert, and delete operations on data accessible through Helidon via HTTP requests. The attack requires low privilege context and network connectivity but no user interaction. Successful exploitation results in both confidentiality and integrity impacts (unauthorized data disclosure and modification), as reflected in the CVSS 3.1 score of 5.4.
Affected products
- Oracle Helidon 4.0.0 through 4.4.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: advisory