Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-21925
4.8MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2026
What is CVE-2026-21925?
An unauthenticated attacker with network access can exploit a vulnerability in Oracle Java SE and GraalVM products, allowing unauthorized access to sensitive data. By leveraging APIs within the affected components, attackers can gain the ability to insert, update, or delete data, as well as read unauthorized content. This vulnerability impacts setups utilizing sandboxed Java applications, presenting significant risks for environments that execute untrusted code from the internet.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.16
Oracle GraalVM for JDK 17.0.17
Oracle GraalVM for JDK 21.0.9