Junglewise Threat Intelligence

CVE-2026-21932: Oracle Java SE improper URI handling in AWT and JavaFX

CVE-2026-21932 · Severity: high · CVSS 7.4 · Published 2026-01-20

Technologies: Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk, Siemens SIMATIC CN 4100. Vendors: Oracle, Red Hat, Siemens.

Executive brief

A vulnerability exists in Oracle Java's AWT and JavaFX components, which are used for building graphical user interfaces. An attacker could trick a user into running malicious code, potentially allowing the attacker to modify or delete sensitive data within the Java environment. This primarily affects desktop applications and web-based Java applets that run untrusted code from the internet.

Technical details

This vulnerability (CWE-1287) stems from improper validation of input types and URI handling within the AWT and JavaFX components of Oracle Java SE and GraalVM. The flaw is easily exploitable by an unauthenticated attacker via multiple network protocols, though it requires human interaction (UI:R) to succeed. A successful exploit results in a scope change (S:C), allowing the attacker to perform unauthorized creation, deletion, or modification of data accessible to the Java runtime. This issue specifically impacts client-side deployments relying on the Java sandbox, such as Java Web Start or applets; server-side deployments running only trusted code are generally not affected. Patches have been released by Oracle and Red Hat (e.g., OpenJDK 11.0.30, 17.0.18).

Affected products

  • Oracle Java SE 8u471, 11.0.29, 17.0.17, 21.0.9, 25.0.1
  • Oracle GraalVM for JDK 17.0.17, 21.0.9
  • Oracle GraalVM Enterprise Edition 21.3.16
  • Red Hat OpenJDK 8u482, 11.0.30, 17.0.18, 21.0.10, 25.0.2

Timeline

  • 2026-01-20: advisory: Initial Oracle advisory published
  • 2026-01-21: patched: Red Hat released updates for OpenJDK 11
  • 2026-01-26: patched: Red Hat released updates for OpenJDK 8 and 17

References

Related threats