Junglewise Threat Intelligence

CVE-2026-73874: Oracle Helidon unauthorized data access in Imperative Web Server

CVE-2026-73874 · Severity: medium · CVSS 5.4 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight web server framework used to build microservices within Oracle Fusion Middleware environments. A vulnerability in the Imperative Web Server component allows a low-privileged attacker to read sensitive data and modify or delete records through HTTP requests, potentially compromising business-critical applications and exposing confidential information.

Technical details

The vulnerability exists in the Imperative Web Server component of Oracle Helidon versions 4.0.0 through 4.4.1. It allows a low-privileged, authenticated attacker with network access to perform unauthorized read, update, insert, and delete operations on data accessible through Helidon via HTTP requests. The attack requires low privilege context and network connectivity but no user interaction. Successful exploitation results in both confidentiality and integrity impacts (unauthorized data disclosure and modification), as reflected in the CVSS 3.1 score of 5.4.

Affected products

  • Oracle Helidon 4.0.0 through 4.4.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory

References

Related threats