Junglewise Threat Intelligence

CVE-2026-83488: Oracle Helidon unauthorized data access in microprofile-security

CVE-2026-83488 · Severity: medium · CVSS 5.4 · Published 2026-09-15

Technologies: Oracle Helidon. Vendors: Oracle.

Executive brief

Helidon is a lightweight Java framework used to build microservices and cloud-native applications. A vulnerability in its security component allows a low-privileged attacker with network access to read sensitive data and modify application records without proper authorization. This could expose customer data or allow unauthorized changes to application state.

Technical details

The vulnerability exists in the helidon-microprofile-security component affecting Helidon versions 4.0.0 through 4.5.4. It is an authorization/access control flaw that allows a low-privileged authenticated attacker to bypass security restrictions via HTTP network access. No special user interaction or high complexity is required; an attacker with valid credentials can perform unauthorized read operations on sensitive data and execute unauthorized create/update/delete operations on accessible application data. Patches are expected from Oracle's security update process.

Affected products

  • Oracle Helidon 4.0.0-4.5.4

Timeline

  • 2026-09-15: disclosed

References

Related threats