Executive brief
Helidon is Oracle's lightweight microservices framework and web server component used in Fusion Middleware. An unauthenticated attacker can send a specially crafted HTTP request over the network to extract sensitive data or gain complete unauthorized access to data accessible by Helidon, without requiring credentials or authentication.
Technical details
This is a confidentiality vulnerability in Oracle Helidon's Imperative Web Server component affecting versions 4.0.0 through 4.4.1. The vulnerability is easily exploitable, requires no authentication, and has a low attack complexity—an attacker can craft a simple HTTP request from the network to bypass access controls and read sensitive data. The attack requires no special privileges, user interaction, or pre-authentication. Successful exploitation grants unauthorized read access to critical or all Helidon-accessible data, with no impact on integrity or availability. No patch information is currently available from the advisory text.
Affected products
- Oracle Helidon 4.0.0 to 4.4.1
Timeline
- 2026-08-18: disclosed