Vulnerability in Helidon for Oracle Fusion Middleware
CVE-2026-83231

7HIGH

Key Information:

Vendor

Oracle

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-83231?

This vulnerability in Oracle's Helidon product from the Fusion Middleware suite allows unauthenticated attackers with HTTP network access to compromise the system. Potential exploitations can lead to unauthorized access to critical information, including the ability to manipulate data through insertions, updates, or deletions. Additionally, there is a risk of causing partial denial of service, affecting the system's availability. The supported versions that are impacted include both 3.0.0 to 3.2.20 and 4.0.0 to 4.5.4 of helidon-dbclient-mongodb.

Affected Version(s)

Helidon 3.0.0 <= 3.2.20

Helidon 4.0.0 <= 4.5.4

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.