Junglewise Threat Intelligence

CVE-2026-87286: Oracle GraalVM compiler vulnerability in Java SE

CVE-2026-87286 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Graalvm. Vendors: Oracle.

Executive brief

Oracle GraalVM is a high-performance Java runtime used to execute Java applications. An unauthenticated attacker can exploit a vulnerability in the compiler component via network access to completely compromise the system, potentially gaining full control over application execution, data access, and availability.

Technical details

A vulnerability exists in the Oracle GraalVM compiler component that can be exploited by an unauthenticated attacker with network access via HTTP. The attack is difficult to exploit and requires no user interaction or authentication. A successful exploit allows an attacker to achieve full system compromise with impacts to confidentiality, integrity, and availability (complete takeover of the affected GraalVM instance). The vulnerability affects Oracle GraalVM 25.0.4.1 running on Oracle Java SE.

Affected products

  • Oracle GraalVM 25.0.4.1

Timeline

  • 2026-09-15: disclosed

References

Related threats