Junglewise Threat Intelligence

CVE-2026-83278: Oracle Helidon Neo4j integration unauthenticated privilege escalation

CVE-2026-83278 · Severity: medium · CVSS 6.8 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

A vulnerability in Oracle Helidon's Neo4j integration component allows an unauthenticated attacker with physical access to the network segment to compromise the Helidon service. An attacker could read, modify, or delete critical data accessible to the application, potentially leading to data loss, unauthorized changes to business information, or complete loss of system integrity.

Technical details

This is a privilege escalation vulnerability in the helidon-integrations-neo4j component of Oracle Helidon. The vulnerability is difficult to exploit and requires physical access to the communication network segment where Helidon is deployed. An unauthenticated attacker can achieve both confidentiality and integrity impacts, gaining the ability to create, delete, or modify critical data within Helidon's data store. The affected versions are Helidon 3.0.0 through 3.2.20 and 4.0.0 through 4.5.4. Oracle has issued a security advisory, though patch availability and workarounds have not been publicly detailed in accessible sources.

Affected products

  • Oracle Helidon 3.0.0-3.2.20 and 4.0.0-4.5.4

Timeline

  • 2026-09-15: disclosed

References

Related threats