Junglewise Threat Intelligence

CVE-2026-73880: Oracle Helidon information disclosure in Imperative Web Server

CVE-2026-73880 · Severity: medium · CVSS 4.4 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight framework for building cloud-native applications and microservices. This vulnerability allows a high-privileged attacker with local access to the infrastructure running Helidon to read sensitive data accessible by the application, including critical business information and configuration data.

Technical details

This is an information disclosure vulnerability in the Helidon Imperative Web Server component affecting versions 4.0.0 through 4.5.0. The vulnerability has a low attack surface, requiring high privileges and local system access (AV:L/PR:H); no user interaction is needed. Successful exploitation allows an attacker to gain unauthorized access to sensitive data processed or stored by Helidon, with confidentiality impact only—integrity and availability are not affected. Patch availability is not detailed in the advisory.

Affected products

  • Oracle Helidon 4.0.0 through 4.5.0

Timeline

  • 2026-08-18: disclosed

References

Related threats