Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-60147

6.5MEDIUM

What is CVE-2026-60147?

This vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition allows unauthenticated attackers with network access to exploit multiple protocols, resulting in unauthorized data manipulation or access. Attackers can leverage APIs within the Security component, potentially impacting systems where untrusted code is executed via sandboxed Java applications. The consequence may lead to unauthorized data modifications and insights into sensitive information. It is crucial for users of affected versions to patch their systems promptly to mitigate risks.

Affected Version(s)

Oracle GraalVM Enterprise Edition 21.3.18

Oracle GraalVM for JDK 17.0.19

Oracle GraalVM for JDK 21.0.11

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.