Remote Code Execution Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-22016

7.5HIGH

What is CVE-2026-22016?

A vulnerability in Oracle Java SE and GraalVM products allows unauthenticated attackers to gain unauthorized access to critical data. This risk arises from easily exploitable interfaces within the JAXP component, enabling attackers to remotely exploit systems over multiple protocols. Specifically, the vulnerability can be triggered by APIs linked to the component, impacting implementations relying on untrusted code or sandbox environments. Active remediation is crucial to safeguard Oracle environments and maintain data integrity.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.17

Oracle GraalVM for JDK 17.0.18

Oracle GraalVM for JDK 21.0.10

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.