Remote Code Execution Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-22016
7.5HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 April 2026
What is CVE-2026-22016?
A vulnerability in Oracle Java SE and GraalVM products allows unauthenticated attackers to gain unauthorized access to critical data. This risk arises from easily exploitable interfaces within the JAXP component, enabling attackers to remotely exploit systems over multiple protocols. Specifically, the vulnerability can be triggered by APIs linked to the component, impacting implementations relying on untrusted code or sandbox environments. Active remediation is crucial to safeguard Oracle environments and maintain data integrity.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.17
Oracle GraalVM for JDK 17.0.18
Oracle GraalVM for JDK 21.0.10