Executive brief
Oracle GraalVM is a high-performance Java runtime used in cloud and enterprise environments. A vulnerability in its compiler component allows unauthenticated attackers to access sensitive data, modify information, and cause service interruptions, potentially compromising applications relying on GraalVM for secure data processing.
Technical details
This is a difficult-to-exploit vulnerability in the Compiler component of Oracle GraalVM for JDK, GraalVM Enterprise Edition, and standalone GraalVM. The vulnerability is network-reachable via HTTP and requires no authentication or user interaction. A successful exploit can result in unauthorized read access to critical data, limited write/delete access to accessible data, and partial denial of service. The attack vector is network-based with high complexity (AC:H). Patches are available for affected versions: GraalVM for JDK 17 (23.0.13.1+), JDK 21 (23.1.12.1+), GraalVM Enterprise Edition (21.3.19.1+), and standalone GraalVM (25.0.4.1+).
Affected products
- Oracle GraalVM for JDK 17: 23.0.13.1 and later
- Oracle GraalVM for JDK 21: 23.1.12.1 and later
- Oracle GraalVM Enterprise Edition 21.3.19.1 and later
- Oracle GraalVM 25.0.4.1 and later
Timeline
- 2026-09-15: disclosed: CVE-2026-83368 publicly disclosed by NVD