Executive brief
A vulnerability exists in the core libraries of Oracle Java SE and GraalVM, which are widely used to run enterprise applications and web services. An attacker could exploit this flaw over a network to modify or delete critical data without needing a username or password. This could lead to data corruption or unauthorized changes to business-critical information managed by Java-based systems.
Technical details
This vulnerability is located in the Libraries component of Oracle Java SE and GraalVM. It is categorized as an integrity-impacting flaw that allows an unauthenticated, remote attacker to compromise the environment via multiple protocols. The attack vector is network-based with low complexity and no user interaction required. Exploitation can occur through APIs, such as web services that process external data, or via sandboxed Java Web Start applications and applets that run untrusted code. Successful exploitation results in unauthorized creation, deletion, or modification of data accessible to the Java runtime.
Affected products
- Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1
- Oracle GraalVM for JDK 17.0.19, 21.0.11
- Oracle GraalVM Enterprise Edition 21.3.18
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle in the July 2026 CPU
- 2026-07-21: advisory: NVD publication date