ZeroHour

CVE-2026-83439

niche

Privilege Escalation in Oracle Helidon IDCS Role Mapper (3.x/4.x)

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83439 is a high-severity (CVSS 8.1) vulnerability in the helidon-security-providers-idcs-mapper component of Oracle Helidon, the Java microservices framework within Oracle Fusion Middleware that maps Oracle Identity Cloud Service (IDCS) identities and roles into application security context. A low-privileged (authenticated) remote attacker exploiting this flaw over HTTP can escalate to gain unauthorized creation, deletion, or modification of critical Helidon-accessible data, as well as unauthorized read access to critical or all Helidon-accessible data. The vulnerability is rated easily exploitable but requires valid low-privilege credentials, and has no availability impact. Affected deployments are Helidon 3.0.0-3.2.20 and 4.0.0-4.5.4 that use the IDCS mapper security provider. There is no known public proof-of-concept, the issue is not on the CISA KEV list, and no in-the-wild exploitation has been reported.

What to do: Upgrade Helidon 3.x deployments from 3.2.20 or earlier and 4.x deployments from 4.5.4 or earlier to the first patched release Oracle ships in its Critical Patch Update, following the CPU advisory for this CVE. Audit IDCS-mapper-based authentication logs for low-privilege accounts that accessed or modified data beyond their assigned roles, and restrict network exposure of Helidon services to trusted clients until patched. If upgrading is delayed, review and tighten IDCS role/group mapping scopes and enforce least-privilege authorization at the gateway.

Affected
Oracle Helidon (Oracle Fusion Middleware, component: helidon-security-providers-idcs-mapper)3.0.0 - 3.2.20
Oracle Helidon (Oracle Fusion Middleware, component: helidon-security-providers-idcs-mapper)4.0.0 - 4.5.4
Estimated exposure
nichelikely low thousands of deployments (order of 1k-10k), unknown precisely — Helidon is a niche open-source Java microservices framework with modest public adoption and no reliable internet-wide fingerprinting in public scan datasets, so exposure is bounded by its small user base rather than measured counts.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.