Junglewise Threat Intelligence

CVE-2026-73883: Oracle Helidon Imperative Web Server information disclosure

CVE-2026-73883 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java web server framework used to build cloud-native applications. This vulnerability allows an unauthenticated attacker to access critical data or sensitive information through the network without requiring valid credentials. Successful exploitation could expose customer data and application secrets accessible to the Helidon server.

Technical details

This is an information disclosure vulnerability in the Helidon Imperative Web Server component affecting versions 3.0.0 through 3.2.17. The vulnerability is easily exploitable and requires only network access via HTTP; no authentication, user interaction, or special configuration is needed. An unauthenticated attacker can retrieve unauthorized access to critical data or complete access to all data accessible by the Helidon instance. The attack vector is network-based with no prerequisites. Oracle has classified this as high severity with a CVSS 3.1 score of 7.5 (high confidentiality impact, no integrity or availability impact).

Affected products

  • Oracle Helidon 3.0.0 through 3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats