Abstract Method Delegation Flaw in Eclipse OpenJ9
CVE-2026-16441

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-16441?

In Eclipse OpenJ9 versions up to 0.60, there exists a flaw when executing class files. If a previously concrete superclass method has been recompiled as abstract, the execution flow is incorrectly redirected to an interface default method. This unexpected behavior can lead to potential exploitation by allowing unintended access and execution of code through the interface, which could compromise the application's integrity.

Affected Version(s)

OpenJ9 0.8.0 < 0.60.0

OpenJ9 0 < 0.8.0

OpenJ9 0.60.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.