Junglewise Threat Intelligence

CVE-2026-21933: Oracle Java SE and GraalVM networking data manipulation

CVE-2026-21933 · Severity: medium · CVSS 6.1 · Published 2026-01-20

Technologies: Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk, Siemens SIMATIC CN 4100. Vendors: Oracle, Siemens.

Executive brief

A vulnerability in the networking component of Oracle Java and GraalVM could allow an attacker to read or modify certain data. This issue is particularly relevant for systems that run untrusted code from the internet or use web services to process external data. Successful exploitation requires a user to perform an action, such as clicking a link or interacting with a malicious application, and could impact other software relying on the Java environment.

Technical details

This vulnerability exists in the Networking component of Oracle Java SE and GraalVM. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the environment, provided there is human interaction (User Interaction: Required). The vulnerability is notable for a 'Scope Change' (S:C), meaning an exploit can impact components beyond the immediate Java runtime. It specifically affects Java deployments that run untrusted code, such as sandboxed Java Web Start applications or applets, and can be triggered through APIs used by web services. Successful exploitation results in unauthorized read, update, insert, or delete access to a subset of accessible data. Oracle addressed this in the January 2026 Critical Patch Update.

Affected products

  • Oracle Java SE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1
  • Oracle GraalVM for JDK 17.0.17, 21.0.9
  • Oracle GraalVM Enterprise Edition 21.3.16
  • Siemens SIMATIC CN 4100 All versions < V5.0

Timeline

  • 2026-01-20: disclosed: Initial disclosure by Oracle
  • 2026-01-20: advisory: Oracle January 2026 Critical Patch Update released
  • 2026-05-12: advisory: Siemens published advisory SSA-032379 noting impact on SIMATIC CN 4100

References

Related threats