Authorization Bypass in Oracle Java SE and GraalVM Products
CVE-2026-21932
7.4HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2026
What is CVE-2026-21932?
A vulnerability exists in Oracle Java SE and GraalVM that allows an unauthenticated attacker with network access to compromise systems through multiple protocols. Successful exploitation requires interaction from a non-attacking user and can lead to unauthorized creation, deletion, or modification of sensitive data. The vulnerability is particularly relevant in scenarios where sandboxed Java applications run untrusted code from the internet, posing significant risks to all data accessible by affected Oracle products.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.16
Oracle GraalVM for JDK 17.0.17
Oracle GraalVM for JDK 21.0.9