Junglewise Threat Intelligence

CVE-2026-73888: Oracle Helidon information disclosure in Imperative Web Server

CVE-2026-73888 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework used to build microservices and web applications. A vulnerability in its Imperative Web Server component allows unauthenticated attackers to read sensitive data through HTTP requests without proper authorization, potentially exposing configuration, credentials, or application data.

Technical details

The vulnerability is an information disclosure flaw in the Helidon Imperative Web Server component affecting versions 4.0.0 through 4.4.1. The issue allows unauthenticated attackers with network access to make HTTP requests that bypass access controls and retrieve restricted data. The attack requires no authentication, user interaction, or special conditions—any network-reachable instance is vulnerable. Successful exploitation results in unauthorized read access to sensitive Helidon data, though integrity and availability are not affected.

Affected products

  • Oracle Helidon 4.0.0 through 4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats