Executive brief
A vulnerability exists in the Java Secure Socket Extension (JSSE) component of Oracle Java SE, which is used to provide secure network communications. An attacker could remotely exploit this flaw to modify or delete critical data within the application. While the attack is difficult to perform, it could compromise the integrity of information processed by web services or other networked Java applications.
Technical details
This vulnerability exists in the Java Secure Socket Extension (JSSE) component of Oracle Java SE and GraalVM. It is an integrity-focused flaw that allows an unauthenticated attacker with network access via TLS to perform unauthorized creation, deletion, or modification of data. The attack is characterized by high complexity (AC:H), meaning it may require specific conditions or timing to succeed. It specifically affects environments where data is supplied to JSSE APIs, such as through web services, but does not impact untrusted Java Web Start applications or applets. Users should apply the July 2026 Oracle Critical Patch Update to mitigate this risk.
Affected products
- Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1
- Oracle GraalVM for JDK 17.0.19, 21.0.11
- Oracle GraalVM Enterprise Edition 21.3.18
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-46968
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released