Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-47010
3.7LOW
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2026-47010?
A vulnerability in Oracle's Java SE and GraalVM products could allow an unauthenticated attacker with network access to exploit issues within the ImageIO component. This could result in unauthorized update, insert, or delete operations on data within the affected systems. The vulnerability is particularly concerning for deployments that utilize sandboxed Java applications or applets, potentially allowing untrusted code to execute and compromise the environment. Efforts to secure such applications must consider this risk to prevent unauthorized data manipulation.
Affected Version(s)
Oracle GraalVM Enterprise Edition 21.3.18
Oracle GraalVM for JDK 17.0.19
Oracle GraalVM for JDK 21.0.11