Executive brief
Helidon is Oracle's lightweight Java framework used to build microservices and web applications. An unauthenticated attacker on the network can exploit this vulnerability through standard HTTP requests to read sensitive data that should be protected, without requiring any credentials or user interaction. This could expose confidential business information or system details hosted by affected applications.
Technical details
This is an information disclosure vulnerability in the Helidon Imperative Web Server component that allows unauthenticated network access via HTTP. The vulnerability has a low attack complexity and requires no privileges or user interaction, making it easily exploitable. An attacker can read a subset of data accessible through Helidon, resulting in unauthorized confidentiality compromise. The affected versions are 3.0.0 through 3.2.18; patches are expected from Oracle's August 2026 security update cycle.
Affected products
- Oracle Helidon 3.0.0-3.2.18
Timeline
- 2026-08-18: disclosed
- 2026-08-18: advisory: Oracle Critical Patch Update