Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-47010

3.7LOW

What is CVE-2026-47010?

A vulnerability in Oracle's Java SE and GraalVM products could allow an unauthenticated attacker with network access to exploit issues within the ImageIO component. This could result in unauthorized update, insert, or delete operations on data within the affected systems. The vulnerability is particularly concerning for deployments that utilize sandboxed Java applications or applets, potentially allowing untrusted code to execute and compromise the environment. Efforts to secure such applications must consider this risk to prevent unauthorized data manipulation.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.18

Oracle GraalVM for JDK 17.0.19

Oracle GraalVM for JDK 21.0.11

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.