Junglewise Threat Intelligence

CVE-2026-83460: Oracle Helidon LRA unauthorized data access

CVE-2026-83460 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Oracle Helidon is a Java framework used to build microservices and cloud applications, with LRA (Long Running Actions) component handling distributed transaction coordination. An unauthenticated attacker with network access can exploit this vulnerability to read sensitive data, or modify/delete data without authorization, potentially disrupting application integrity and exposing confidential information.

Technical details

This vulnerability in the Helidon LRA component is easily exploitable over HTTP by an unauthenticated attacker with network access. The issue allows unauthorized read, insert, update, and delete operations on data accessible through Helidon, indicating either an authentication bypass or an improperly secured API endpoint. The vulnerability affects Helidon versions 4.0.0 through 4.5.4. The attack requires no user interaction and has no access control preconditions. Oracle has issued a security advisory detailing the vulnerability, though patches and mitigation guidance are referenced but not directly accessible in the provided materials.

Affected products

  • Oracle Helidon 4.0.0 to 4.5.4

Timeline

  • 2026-09-15: disclosed

References

Related threats