Executive brief
Oracle GraalVM is a high-performance Java runtime environment used by organizations to execute Java applications. An unauthenticated attacker can exploit a vulnerability in the compiler component via network access, potentially achieving complete control of the affected system including data theft, modification, and service disruption.
Technical details
A difficult-to-exploit vulnerability exists in the Oracle GraalVM compiler component that allows unauthenticated remote code execution over the network via HTTP. The vulnerability requires no user interaction and no authentication, but may require specific preconditions to trigger. Successful exploitation results in arbitrary code execution with full system compromise including confidentiality, integrity, and availability impacts. The affected version is GraalVM 25.0.4.1; patch availability status is not explicitly confirmed in the advisory.
Affected products
- Oracle GraalVM 25.0.4.1
Timeline
- 2026-09-15: disclosed