Executive brief
A vulnerability exists in the Security component of Oracle Java and GraalVM, which are widely used platforms for running business applications and web services. An attacker could exploit this flaw to gain unauthorized access to view, modify, or delete sensitive data processed by these applications. This issue also affects desktop environments that run untrusted Java code from the internet, potentially bypassing security protections designed to keep the system safe.
Technical details
A vulnerability in the Security component of Oracle Java SE and GraalVM allows unauthenticated attackers with network access via multiple protocols to compromise the environment. The flaw is easily exploitable and can lead to unauthorized read, insert, update, or delete access to a subset of data accessible by the Java runtime. The vulnerability is particularly relevant to web services that pass data to affected Security APIs and to client-side deployments running sandboxed Java Web Start applications or applets that execute untrusted code. Affected versions include Java SE 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; GraalVM for JDK 17.0.19 and 21.0.11; and GraalVM Enterprise Edition 21.3.18. Users should apply the July 2026 Oracle Critical Patch Update.
Affected products
- Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1
- Oracle GraalVM for JDK 17.0.19, 21.0.11
- Oracle Corporation GraalVM Enterprise Edition 21.3.18
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60147 by Oracle.
- 2026-07-21: advisory: Oracle Critical Patch Update (CPU) released.