Junglewise Threat Intelligence

CVE-2026-73881: Oracle Helidon unauthorized data access vulnerability

CVE-2026-73881 · Severity: medium · CVSS 5.4 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight web server component used in Oracle Fusion Middleware to handle HTTP requests and serve web applications. A vulnerability in versions 4.0.0 through 4.4.1 allows a low-privileged attacker with network access to read sensitive data and make unauthorized modifications to information stored within the application, potentially exposing customer data or disrupting application functionality.

Technical details

This vulnerability in the Helidon Imperative Web Server component allows an authenticated attacker with low privileges to bypass access controls via HTTP requests. The attack requires network access but no additional user interaction; the attacker must already have valid credentials or low-privilege account access. Successful exploitation results in unauthorized read access to a subset of Helidon-accessible data (confidentiality impact) and unauthorized insert, update, or delete operations (integrity impact). The root cause appears to be insufficient authorization checks on data operations. Patches are available for affected versions 4.0.0 through 4.4.1.

Affected products

  • Oracle Helidon 4.0.0 to 4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats