Executive brief
Oracle Helidon, an open-source Java framework for building microservices and cloud-native applications, contains a vulnerability that allows unauthenticated attackers to read, modify, or delete sensitive data accessible through the web server. An attacker on the network can exploit this flaw without credentials to compromise data confidentiality and integrity, potentially impacting applications and systems that depend on Helidon.
Technical details
The vulnerability is an authorization bypass in Helidon's Imperative Web Server component affecting versions 4.0.0 through 4.5.0. The flaw allows unauthenticated attackers with network access via HTTP to perform unauthorized read, update, insert, and delete operations on Helidon-accessible data. The attack requires no user interaction and no special privileges. Successful exploitation results in confidentiality and integrity impacts (CVSS 3.1 score 7.2), with potential scope change affecting dependent products. A patch or mitigation should be available from Oracle.
Affected products
- Oracle Helidon 4.0.0-4.5.0
Timeline
- 2026-08-18: disclosed