Junglewise Threat Intelligence

CVE-2026-83231: Oracle Helidon MongoDB DBClient unauthorized data access vulnerability

CVE-2026-83231 · Severity: high · CVSS 7 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a lightweight Java framework used to build cloud-native microservices. A flaw in its MongoDB database client component allows unauthenticated attackers over the network to access, modify, or delete sensitive data and cause service disruptions. This could lead to exposure of customer data, unauthorized system modification, or application downtime.

Technical details

The vulnerability exists in the helidon-dbclient-mongodb component of Oracle Helidon versions 3.0.0–3.2.20 and 4.0.0–4.5.4. It is a network-accessible flaw that requires difficult exploitation conditions (high complexity) but no authentication or user interaction. An unauthenticated attacker with network access via HTTP can exploit this to read critical data, modify or insert data, and cause partial service denial. The vulnerability affects confidentiality, integrity, and availability of Helidon and its data stores.

Affected products

  • Oracle Helidon 3.0.0-3.2.20, 4.0.0-4.5.4

Timeline

  • 2026-09-15: disclosed

References

Related threats