Junglewise Threat Intelligence

CVE-2026-73875: Oracle Helidon unauthorized data access via HTTP

CVE-2026-73875 · Severity: high · CVSS 7.2 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight web server framework used to build cloud-native applications. A flaw in the Helidon web server component allows attackers on the network to read, modify, or delete data without authentication, potentially exposing sensitive information from the application and any downstream systems that depend on it.

Technical details

This is an authentication bypass or authorization vulnerability in the Imperative Web Server component of Oracle Helidon affecting versions 3.0.0 through 3.2.18. An unauthenticated attacker with network access can exploit the flaw via HTTP requests to perform unauthorized data read, update, insert, and delete operations. The vulnerability has a changed scope, meaning successful exploitation can impact additional Oracle Fusion Middleware products beyond Helidon itself. No exploitation in the wild has been reported at the time of publication.

Affected products

  • Oracle Helidon 3.0.0 to 3.2.18

Timeline

  • 2026-08-18: disclosed

References

Related threats