Junglewise Threat Intelligence

CVE-2026-73884: Oracle Helidon unauthorized data access via HTTP

CVE-2026-73884 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is Oracle's lightweight microservices framework and web server component used in Fusion Middleware. An unauthenticated attacker can send a specially crafted HTTP request over the network to extract sensitive data or gain complete unauthorized access to data accessible by Helidon, without requiring credentials or authentication.

Technical details

This is a confidentiality vulnerability in Oracle Helidon's Imperative Web Server component affecting versions 4.0.0 through 4.4.1. The vulnerability is easily exploitable, requires no authentication, and has a low attack complexity—an attacker can craft a simple HTTP request from the network to bypass access controls and read sensitive data. The attack requires no special privileges, user interaction, or pre-authentication. Successful exploitation grants unauthorized read access to critical or all Helidon-accessible data, with no impact on integrity or availability. No patch information is currently available from the advisory text.

Affected products

  • Oracle Helidon 4.0.0 to 4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats