Junglewise Threat Intelligence

CVE-2026-73885: Oracle Helidon authorization bypass in HTTP handling

CVE-2026-73885 · Severity: high · CVSS 7.2 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework for building web applications and microservices. An unauthenticated attacker can bypass authorization controls over the network, allowing unauthorized reading, modification, and deletion of data accessible through the web server. This vulnerability can impact not only Helidon itself but also downstream applications and services that depend on it.

Technical details

This vulnerability is an authorization bypass in Helidon's Imperative Web Server component that affects versions 3.0.0 through 3.2.17. The flaw allows unauthenticated attackers with network access to exploit the vulnerability via HTTP requests without requiring authentication or user interaction. Successful exploitation enables unauthorized read access to sensitive data, as well as unauthorized update, insert, and delete operations. The scope change indicates that while the vulnerability exists in Helidon, attacks can cascade to affect other connected products and services. Patches should be available from Oracle; users are advised to upgrade to patched versions beyond 3.2.17.

Affected products

  • Oracle Helidon 3.0.0 through 3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats