Executive brief
Helidon is a lightweight web server component used in Oracle Fusion Middleware to handle HTTP requests and serve web applications. An unauthenticated attacker on the network can access this server over HTTP and read sensitive data that should not be exposed, potentially compromising application confidentiality without requiring authentication or user interaction.
Technical details
This vulnerability in the Helidon Imperative Web Server allows unauthenticated information disclosure through an HTTP-accessible interface. The flaw permits remote network attackers to read a subset of accessible data without authentication, authentication bypass, or user interaction required. Affected versions range from 4.0.0 through 4.4.1. The root cause and specific attack vector are not detailed in the advisory, but the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the vulnerability is easily exploitable via network access with no prerequisites. Patches are expected to be available through Oracle's standard security update channels; users should monitor Oracle's security alerts for remediation guidance.
Affected products
- Oracle Helidon 4.0.0 through 4.4.1
Timeline
- 2026-08-18: disclosed