Junglewise Threat Intelligence

CVE-2026-73899: Oracle Helidon unauthorized information disclosure via HTTP

CVE-2026-73899 · Severity: medium · CVSS 5.3 · Published 2026-08-18

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is Oracle's lightweight Java framework used to build microservices and web applications. An unauthenticated attacker on the network can exploit this vulnerability through standard HTTP requests to read sensitive data that should be protected, without requiring any credentials or user interaction. This could expose confidential business information or system details hosted by affected applications.

Technical details

This is an information disclosure vulnerability in the Helidon Imperative Web Server component that allows unauthenticated network access via HTTP. The vulnerability has a low attack complexity and requires no privileges or user interaction, making it easily exploitable. An attacker can read a subset of data accessible through Helidon, resulting in unauthorized confidentiality compromise. The affected versions are 3.0.0 through 3.2.18; patches are expected from Oracle's August 2026 security update cycle.

Affected products

  • Oracle Helidon 3.0.0-3.2.18

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory: Oracle Critical Patch Update

References

Related threats