Junglewise Threat Intelligence

CVE-2026-73876: Oracle Helidon unauthorized data access vulnerability

CVE-2026-73876 · Severity: high · CVSS 7.2 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon, an open-source Java framework for building microservices and cloud-native applications, contains a vulnerability that allows unauthenticated attackers to read, modify, or delete sensitive data accessible through the web server. An attacker on the network can exploit this flaw without credentials to compromise data confidentiality and integrity, potentially impacting applications and systems that depend on Helidon.

Technical details

The vulnerability is an authorization bypass in Helidon's Imperative Web Server component affecting versions 4.0.0 through 4.5.0. The flaw allows unauthenticated attackers with network access via HTTP to perform unauthorized read, update, insert, and delete operations on Helidon-accessible data. The attack requires no user interaction and no special privileges. Successful exploitation results in confidentiality and integrity impacts (CVSS 3.1 score 7.2), with potential scope change affecting dependent products. A patch or mitigation should be available from Oracle.

Affected products

  • Oracle Helidon 4.0.0-4.5.0

Timeline

  • 2026-08-18: disclosed

References

Related threats