Executive brief
Oracle Helidon is a lightweight Java web server framework used to build cloud-native applications. This vulnerability allows an unauthenticated attacker to access critical data or sensitive information through the network without requiring valid credentials. Successful exploitation could expose customer data and application secrets accessible to the Helidon server.
Technical details
This is an information disclosure vulnerability in the Helidon Imperative Web Server component affecting versions 3.0.0 through 3.2.17. The vulnerability is easily exploitable and requires only network access via HTTP; no authentication, user interaction, or special configuration is needed. An unauthenticated attacker can retrieve unauthorized access to critical data or complete access to all data accessible by the Helidon instance. The attack vector is network-based with no prerequisites. Oracle has classified this as high severity with a CVSS 3.1 score of 7.5 (high confidentiality impact, no integrity or availability impact).
Affected products
- Oracle Helidon 3.0.0 through 3.2.17
Timeline
- 2026-08-18: disclosed