Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-22013
5.3MEDIUM
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 April 2026
What is CVE-2026-22013?
A vulnerability in Oracle Java SE and GraalVM products enables unauthenticated attackers with network access to potentially gain unauthorized access. This vulnerability primarily affects Java deployments operating in a dynamic environment, such as sandboxed applications that may execute untrusted code. Successful exploitation requires interaction from a user other than the attacker, highlighting the importance of user awareness in preventing breaches. Those deploying Java applications should review their configurations and ensure they are not running untrusted code to mitigate risks inherent to this vulnerability.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.17
Oracle GraalVM for JDK 17.0.18
Oracle GraalVM for JDK 21.0.10