Executive brief
Helidon is a lightweight web server framework used to build microservices and cloud-native applications. An unauthenticated attacker on the network can exploit this vulnerability via HTTP to read, modify, or delete sensitive data processed by Helidon applications, and also trigger service disruptions. No authentication or user interaction is required to launch an attack.
Technical details
This vulnerability in Oracle Helidon's Imperative Web Server component allows unauthenticated remote attackers to bypass access controls via the HTTP protocol. The flaw permits unauthorized data access (read), modification (insert/update), and deletion operations on data accessible to Helidon, as well as partial denial of service attacks. The vulnerability affects versions 4.0.0 through 4.4.1 and requires only network access to exploit; no prior authentication or special preconditions are needed. Patched versions beyond 4.4.1 are expected to be available from Oracle.
Affected products
- Oracle Helidon 4.0.0-4.4.1
Timeline
- 2026-08-18: disclosed