Junglewise Threat Intelligence

CVE-2026-62574: Oracle Java SE and GraalVM compromise in Install component

CVE-2026-62574 · Severity: high · CVSS 7.8 · Published 2026-07-21

Executive brief

A vulnerability in the installation component of Oracle Java SE and GraalVM could allow a user with basic access to the underlying computer system to take full control of the Java environment. This could lead to unauthorized access to sensitive data, modification of application logic, or disruption of services running on the affected software. Organizations using these versions should apply the latest security updates from Oracle to prevent local attackers from compromising their Java infrastructure.

Technical details

A vulnerability exists in the 'Install' component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. The flaw is categorized as easily exploitable and requires the attacker to have local logon credentials to the infrastructure where the software is executing. Successful exploitation allows a low-privileged attacker to achieve a complete compromise of the Java environment, impacting confidentiality, integrity, and availability. The vulnerability affects multiple major versions including Java 8, 11, 17, 21, 25, and 26. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle Java SE 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1
  • Oracle GraalVM for JDK 17.0.19, 21.0.11
  • Oracle Corporation GraalVM Enterprise Edition 21.3.18

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats