Junglewise Threat Intelligence

CVE-2026-73892: Oracle Helidon unauthorized data access in Imperative Web Server

CVE-2026-73892 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework used to build microservices and web applications. A network-accessible vulnerability in its Imperative Web Server component allows unauthenticated attackers to read sensitive data and make unauthorized modifications to application data without requiring authentication or user interaction. This could expose confidential business information or enable attackers to tamper with application functionality and data integrity.

Technical details

The vulnerability is an unauthenticated data access flaw in the Imperative Web Server component of Helidon versions 4.0.0 through 4.4.1. It can be exploited over HTTP by a remote network attacker without authentication, authentication bypass, or user interaction required. Successful exploitation results in unauthorized read access to a subset of Helidon-accessible data and unauthorized update, insert, or delete operations on some Helidon data. The exact root cause and vulnerable code path are not disclosed in available sources. Patches are expected in Oracle's security updates; versions 4.4.2 and later are likely unaffected.

Affected products

  • Oracle Helidon 4.0.0 to 4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats