Junglewise Threat Intelligence

CVE-2026-73877: Oracle Helidon unauthorized data access

CVE-2026-73877 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a lightweight web server framework used in Oracle Fusion Middleware to power microservices and web applications. An unauthenticated attacker with network access can exploit this vulnerability to read sensitive data that should be protected, potentially exposing confidential business information or customer data without requiring any special privileges or credentials.

Technical details

This is an information disclosure vulnerability in the Helidon Imperative Web Server (versions 3.0.0 through 3.2.17) that allows unauthorized read access to a subset of data accessible to the web server. The vulnerability is easily exploitable via HTTP and requires no authentication, no special configuration, and no user interaction. An unauthenticated attacker with network access can directly trigger the vulnerability to read sensitive data. Patch availability and remediation details should be confirmed via Oracle's official security advisories.

Affected products

  • Oracle Helidon 3.0.0 through 3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats