Junglewise Threat Intelligence

CVE-2026-73886: Oracle Helidon unspecified vulnerability in Imperative Web Server

CVE-2026-73886 · Severity: high · CVSS 7.2 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework used to build microservices and cloud-native applications. This vulnerability in the Imperative Web Server component allows unauthenticated attackers to read and modify sensitive data accessible to the service, potentially affecting systems that depend on Helidon for handling HTTP traffic and data access.

Technical details

An easily exploitable vulnerability exists in Oracle Helidon's Imperative Web Server component (versions 4.0.0 through 4.4.1) that can be triggered remotely via HTTP without authentication. The vulnerability has a scope change, meaning successful exploitation may impact additional products beyond Helidon itself. Attackers can achieve unauthorized read access to a subset of accessible data and unauthorized update, insert, or delete operations on some Helidon-accessible data. A patch or fix status is not explicitly stated in the advisory.

Affected products

  • Oracle Helidon 4.0.0-4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats