Junglewise Threat Intelligence

CVE-2026-73897: Oracle Helidon unauthorized data access in Imperative Web Server

CVE-2026-73897 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a web server component used in Oracle Fusion Middleware to handle HTTP requests and serve web applications. An unauthenticated attacker with network access can exploit this vulnerability to read sensitive data and modify application data without authorization, potentially compromising the confidentiality and integrity of business-critical information.

Technical details

This vulnerability in Oracle Helidon's Imperative Web Server component allows unauthenticated attackers to bypass access controls through an easily exploitable network-based attack vector via HTTP. The vulnerability results in unauthorized read and write access (create, update, delete) to data accessible through the web server. No user interaction is required and the attack complexity is low, meaning a straightforward HTTP request can trigger the vulnerability. The vulnerability affects versions 4.0.0 through 4.4.1 of Helidon.

Affected products

  • Oracle Helidon 4.0.0 to 4.4.1

Timeline

  • 2026-08-18: disclosed

References

Related threats