Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-21925
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2026
What is CVE-2026-21925?
An unauthenticated attacker with network access can exploit a vulnerability in Oracle Java SE and GraalVM products, allowing unauthorized access to sensitive data. By leveraging APIs within the affected components, attackers can gain the ability to insert, update, or delete data, as well as read unauthorized content. This vulnerability impacts setups utilizing sandboxed Java applications, presenting significant risks for environments that execute untrusted code from the internet.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.16
Oracle GraalVM for JDK 17.0.17
Oracle GraalVM for JDK 21.0.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved