Executive brief
Oracle Java SE and GraalVM are widely used platforms for running enterprise applications and web services. A vulnerability in the Remote Method Invocation (RMI) component could allow an attacker to remotely access or modify certain application data. While difficult to exploit, this flaw could lead to unauthorized data manipulation or information disclosure in environments that process untrusted data or rely on the Java sandbox for security.
Technical details
A vulnerability exists in the Remote Method Invocation (RMI) component of Oracle Java SE and GraalVM. The flaw is characterized by Oracle as difficult to exploit but allows an unauthenticated attacker with network access via multiple protocols to compromise the environment. Successful exploitation can result in unauthorized read, update, insert, or delete access to a subset of accessible data. The vulnerability is particularly relevant to Java deployments that load untrusted code (such as sandboxed applets or Web Start applications) or web services that supply data to RMI APIs. Siemens has also identified this as an inherited vulnerability in their SIMATIC CN 4100 communication nodes. Oracle addressed these issues in the January 2026 Critical Patch Update.
Affected products
- Oracle Java SE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1
- Oracle GraalVM for JDK 17.0.17, 21.0.9
- Oracle GraalVM Enterprise Edition 21.3.16
- Siemens SIMATIC CN 4100 All versions < V5.0
Timeline
- 2026-01-20: disclosed: Initial disclosure by Oracle
- 2026-01-20: advisory: NVD published CVE-2026-21925
- 2026-05-12: advisory: Siemens published advisory SSA-032379 noting impact on SIMATIC CN 4100