Executive brief
Oracle Helidon is a Java framework component used in Oracle Fusion Middleware for building microservices and managing API security through identity and access management. A vulnerability in the IDCS (Identity Cloud Service) mapper authentication provider allows a low-privilege attacker to bypass security controls and read, modify, or delete sensitive data accessible to the application without proper authorization.
Technical details
This vulnerability exists in the helidon-security-providers-idcs-mapper component and affects Helidon versions 3.0.0 through 3.2.20 and 4.0.0 through 4.5.4. It is an authentication/authorization bypass flaw in the IDCS provider mapper that can be exploited by a low-privileged attacker with network access via HTTP. The vulnerability requires minimal privileges (PR:L) and no user interaction, allowing an attacker to achieve high confidentiality and integrity impact over data accessible through the Helidon application. Patches are available for affected versions.
Affected products
- Oracle Helidon 3.0.0-3.2.20, 4.0.0-4.5.4
Timeline
- 2026-09-15: disclosed