Vulnerability in Oracle Java SE and GraalVM Enterprise Edition
CVE-2026-22003

6MEDIUM

What is CVE-2026-22003?

An improper input validation vulnerability exists in Oracle Java SE and Oracle GraalVM Enterprise Edition. This issue affects specific versions and primarily impacts environments where untrusted code is executed. Attackers with low privileges can exploit this vulnerability to potentially create, delete, or modify critical data, affecting the integrity and availability of the system. Notably, successful exploitation requires human interaction from another individual, making the attack vector more complex. This vulnerability is particularly relevant in client deployments where Java Web Start applications or sandboxed Java applets operate, as they often handle untrusted code sourced from the internet. It does not apply to server-side deployments running only trusted code.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.17

Oracle Java SE 8u481

Oracle Java SE 8u481-b50

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.