Junglewise Threat Intelligence

CVE-2026-83439: Oracle Helidon authentication bypass in IDCS mapper

CVE-2026-83439 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a Java framework component used in Oracle Fusion Middleware for building microservices and managing API security through identity and access management. A vulnerability in the IDCS (Identity Cloud Service) mapper authentication provider allows a low-privilege attacker to bypass security controls and read, modify, or delete sensitive data accessible to the application without proper authorization.

Technical details

This vulnerability exists in the helidon-security-providers-idcs-mapper component and affects Helidon versions 3.0.0 through 3.2.20 and 4.0.0 through 4.5.4. It is an authentication/authorization bypass flaw in the IDCS provider mapper that can be exploited by a low-privileged attacker with network access via HTTP. The vulnerability requires minimal privileges (PR:L) and no user interaction, allowing an attacker to achieve high confidentiality and integrity impact over data accessible through the Helidon application. Patches are available for affected versions.

Affected products

  • Oracle Helidon 3.0.0-3.2.20, 4.0.0-4.5.4

Timeline

  • 2026-09-15: disclosed

References

Related threats