Network Access Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-47021

5.3MEDIUM

What is CVE-2026-47021?

A vulnerability exists in Oracle Java SE and GraalVM products that allows an unauthenticated attacker with network access to exploit the system. This flaw can lead to a partial denial of service, impacting the availability of the affected Oracle products. The exploitation can occur via multiple protocols and utilizes APIs located in the vulnerable component. Java deployments, particularly those involving sandboxed applications, are at risk when they load untrusted code from external sources, which may bypass security provisions. Supported versions of Oracle Java SE, GraalVM for JDK, and GraalVM Enterprise Edition are affected, making it imperative for users to assess their security posture and apply the necessary updates.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.18

Oracle GraalVM for JDK 17.0.19

Oracle GraalVM for JDK 21.0.11

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.