Junglewise Threat Intelligence

CVE-2026-73891: Oracle Helidon remote data manipulation and denial of service

CVE-2026-73891 · Severity: high · CVSS 7.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a lightweight web server framework used to build microservices and cloud-native applications. An unauthenticated attacker on the network can exploit this vulnerability via HTTP to read, modify, or delete sensitive data processed by Helidon applications, and also trigger service disruptions. No authentication or user interaction is required to launch an attack.

Technical details

This vulnerability in Oracle Helidon's Imperative Web Server component allows unauthenticated remote attackers to bypass access controls via the HTTP protocol. The flaw permits unauthorized data access (read), modification (insert/update), and deletion operations on data accessible to Helidon, as well as partial denial of service attacks. The vulnerability affects versions 4.0.0 through 4.4.1 and requires only network access to exploit; no prior authentication or special preconditions are needed. Patched versions beyond 4.4.1 are expected to be available from Oracle.

Affected products

  • Oracle Helidon 4.0.0-4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats