Impact
Helidon includes an authorization bypass that permits a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data, effectively granting full access to all data managed by the instance. This is an improper authorization weakness (CWE‑284) that can compromise both confidentiality and integrity of Helidon data. The vulnerability allows non‑admin users to perform privileged operations that they should not have the right to execute, thereby sustaining an elevated foothold in the application.
Affected Systems
Affected systems are Oracle Helidon versions 3.0.0 through 3.2.20 and 4.0.0 through 4.5.4, as stated in the vendor advisory and CNA information.
Risk and Exploitability
The CVSS base score of 8.1 indicates significant risk, requiring only normal network access and low privilege. EPSS is under 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited yet. The likely attack vector is over HTTP, where a low‑privileged actor can send crafted requests to the helidon‑security‑providers‑idcs‑mapper component to bypass authorization checks and modify data.
OpenCVE Enrichment