Network Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-21933
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 20 January 2026
What is CVE-2026-21933?
A vulnerability exists in Oracle's Java SE and GraalVM products, allowing unauthenticated attackers with network access to exploit the affected components. This vulnerability, which requires human interaction to be successfully exploited, can lead to unauthorized operations such as update, insert, or delete actions on accessible data, alongside unauthorized read access. The issue significantly impacts the security of Java deployments, particularly those running in sandboxed environments, where untrusted code may be executed. Attackers could leverage this vulnerability via web services that interface with the Java APIs. Users must secure their systems against potential exploitation to mitigate risks associated with compromised network access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.16
Oracle GraalVM for JDK 17.0.17
Oracle GraalVM for JDK 21.0.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved