CVE-2026-83439
nichePrivilege Escalation in Oracle Helidon IDCS Role Mapper (3.x/4.x)
CVE-2026-83439 is a high-severity (CVSS 8.1) vulnerability in the helidon-security-providers-idcs-mapper component of Oracle Helidon, the Java microservices framework within Oracle Fusion Middleware that maps Oracle Identity Cloud Service (IDCS) identities and roles into application security context. A low-privileged (authenticated) remote attacker exploiting this flaw over HTTP can escalate to gain unauthorized creation, deletion, or modification of critical Helidon-accessible data, as well as unauthorized read access to critical or all Helidon-accessible data. The vulnerability is rated easily exploitable but requires valid low-privilege credentials, and has no availability impact. Affected deployments are Helidon 3.0.0-3.2.20 and 4.0.0-4.5.4 that use the IDCS mapper security provider. There is no known public proof-of-concept, the issue is not on the CISA KEV list, and no in-the-wild exploitation has been reported.
What to do: Upgrade Helidon 3.x deployments from 3.2.20 or earlier and 4.x deployments from 4.5.4 or earlier to the first patched release Oracle ships in its Critical Patch Update, following the CPU advisory for this CVE. Audit IDCS-mapper-based authentication logs for low-privilege accounts that accessed or modified data beyond their assigned roles, and restrict network exposure of Helidon services to trusted clients until patched. If upgrading is delayed, review and tighten IDCS role/group mapping scopes and enforce least-privilege authorization at the gateway.
| Oracle Helidon (Oracle Fusion Middleware, component: helidon-security-providers-idcs-mapper) | 3.0.0 - 3.2.20 |
| Oracle Helidon (Oracle Fusion Middleware, component: helidon-security-providers-idcs-mapper) | 4.0.0 - 4.5.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.