Executive brief
A vulnerability exists in the ImageIO component of Oracle Java SE and GraalVM, which are widely used platforms for running enterprise applications and web services. An attacker could potentially modify or delete certain data accessible to the Java environment, though the attack is considered difficult to execute. This issue primarily impacts the integrity of data processed by applications that handle images from untrusted sources or run sandboxed code.
Technical details
This vulnerability affects the ImageIO component within Oracle Java SE and GraalVM. It is characterized by a high attack complexity (AC:H), meaning successful exploitation requires specific conditions or significant effort from an unauthenticated attacker. The flaw can be triggered via multiple protocols, typically through web services that pass untrusted data to ImageIO APIs or via sandboxed Java Web Start applications and applets. Successful exploitation results in unauthorized update, insert, or delete access to a subset of data accessible to the Java runtime environment. The vulnerability is addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1
- Oracle GraalVM for JDK 17.0.19, 21.0.11
- Oracle Corporation GraalVM Enterprise Edition 21.3.18
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-47010 by Oracle
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released