Executive brief
Oracle Helidon is a lightweight web framework used to build microservices and cloud-native applications. An unauthenticated remote attacker can exploit a network-accessible vulnerability to read, modify, or delete data within Helidon applications and cause service disruptions, without requiring credentials or user interaction.
Technical details
The vulnerability is an easily exploitable flaw in Helidon's Imperative Web Server component affecting versions 4.0.0 through 4.4.1. An unauthenticated attacker with network access via HTTP can trigger unauthorized data operations (create, read, update, delete) and cause partial denial of service. The attack requires no authentication, user interaction, or special conditions (CVSS vector AV:N/AC:L/PR:N/UI:N). The exact vulnerability mechanism is not disclosed in available references, but the impact includes confidentiality, integrity, and availability violations. Patched versions beyond 4.4.1 are expected to be available from Oracle.
Affected products
- Oracle Helidon 4.0.0 to 4.4.1
Timeline
- 2026-08-18: disclosed