Security Vulnerability in Oracle Java SE and GraalVM Products
CVE-2026-60589

3.7LOW

What is CVE-2026-60589?

A vulnerability has been identified in Oracle Java SE and GraalVM products, which allows an unauthenticated attacker with network access to compromise these systems. This issue primarily affects several supported versions of Oracle Java SE and GraalVM, leading to unauthorized read access to sensitive data within the affected components. Exploitation of this vulnerability occurs through API interaction without relying on untrusted Java Web Start applications or applets. Consequently, ensuring the security of these applications is paramount to protect against potential data breaches.

Affected Version(s)

Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Oracle Java SE:8u501

Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Oracle Java SE:11.0.32

Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition Oracle Java SE:17.0.20

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.