Junglewise Threat Intelligence

CVE-2026-73895: Oracle Helidon unauthorized data access in Imperative Web Server

CVE-2026-73895 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight microservices framework used to build web applications and services. A vulnerability in its Imperative Web Server component allows unauthenticated attackers on the network to read sensitive data accessible through Helidon without credentials or user interaction, potentially exposing application configuration, credentials, or other confidential information.

Technical details

The vulnerability is an unauthorized information disclosure flaw in Helidon's Imperative Web Server component affecting versions 3.0.0 through 3.2.17. The vulnerability is easily exploitable via HTTP, requires no authentication or user interaction, and can be triggered by an unauthenticated network-based attacker. Successful exploitation grants read access to a subset of Helidon-accessible data. The attack vector is network-based with low attack complexity and no privileges required. Oracle has classified this as a confidentiality impact with a CVSS 3.1 base score of 5.3. Patch availability status from Oracle is not confirmed in the available references.

Affected products

  • Oracle Helidon 3.0.0-3.2.17

Timeline

  • 2026-08-18: disclosed

References

Related threats