Junglewise Threat Intelligence

CVE-2026-83368: Oracle GraalVM Compiler vulnerability allowing unauthorized data access

CVE-2026-83368 · Severity: high · CVSS 7 · Published 2026-09-15

Technologies: Oracle Graalvm, Oracle GraalVM Enterprise Edition, Oracle Graalvm For Jdk. Vendors: Oracle.

Executive brief

Oracle GraalVM is a high-performance Java runtime used in cloud and enterprise environments. A vulnerability in its compiler component allows unauthenticated attackers to access sensitive data, modify information, and cause service interruptions, potentially compromising applications relying on GraalVM for secure data processing.

Technical details

This is a difficult-to-exploit vulnerability in the Compiler component of Oracle GraalVM for JDK, GraalVM Enterprise Edition, and standalone GraalVM. The vulnerability is network-reachable via HTTP and requires no authentication or user interaction. A successful exploit can result in unauthorized read access to critical data, limited write/delete access to accessible data, and partial denial of service. The attack vector is network-based with high complexity (AC:H). Patches are available for affected versions: GraalVM for JDK 17 (23.0.13.1+), JDK 21 (23.1.12.1+), GraalVM Enterprise Edition (21.3.19.1+), and standalone GraalVM (25.0.4.1+).

Affected products

  • Oracle GraalVM for JDK 17: 23.0.13.1 and later
  • Oracle GraalVM for JDK 21: 23.1.12.1 and later
  • Oracle GraalVM Enterprise Edition 21.3.19.1 and later
  • Oracle GraalVM 25.0.4.1 and later

Timeline

  • 2026-09-15: disclosed: CVE-2026-83368 publicly disclosed by NVD

References

Related threats