Executive brief
Oracle Helidon is a Java-based web server component used in Oracle Fusion Middleware to handle HTTP traffic and serve web applications. An unauthenticated network attacker can exploit this vulnerability to create, delete, or modify critical data without authorization, potentially compromising the integrity of business-critical applications and databases accessible through Helidon.
Technical details
This integrity vulnerability in Oracle Helidon's Imperative Web Server (versions 4.0.0 through 4.5.0) allows unauthenticated attackers to modify or delete critical data via HTTP. The vulnerability is easily exploitable with no authentication required, no special access privileges needed, and no user interaction required—network access alone is sufficient. An attacker can achieve unauthorized creation, deletion, or modification of sensitive data accessible to the Helidon server. Patches are available from Oracle as part of their August 2026 security update.
Affected products
- Oracle Helidon 4.0.0 to 4.5.0
Timeline
- 2026-08-18: disclosed