Executive brief
Oracle Helidon is a web server component used in Oracle Fusion Middleware to handle HTTP requests and serve web applications. An unauthenticated attacker with network access can exploit this vulnerability to read sensitive data and modify application data without authorization, potentially compromising the confidentiality and integrity of business-critical information.
Technical details
This vulnerability in Oracle Helidon's Imperative Web Server component allows unauthenticated attackers to bypass access controls through an easily exploitable network-based attack vector via HTTP. The vulnerability results in unauthorized read and write access (create, update, delete) to data accessible through the web server. No user interaction is required and the attack complexity is low, meaning a straightforward HTTP request can trigger the vulnerability. The vulnerability affects versions 4.0.0 through 4.4.1 of Helidon.
Affected products
- Oracle Helidon 4.0.0 to 4.4.1
Timeline
- 2026-08-18: disclosed