Junglewise Threat Intelligence

CVE-2026-87288: Oracle GraalVM compiler remote code execution

CVE-2026-87288 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Graalvm. Vendors: Oracle.

Executive brief

Oracle GraalVM is a high-performance Java runtime and compiler technology used in enterprise Java applications. A network-accessible vulnerability in the compiler component allows an unauthenticated attacker to achieve complete takeover of the GraalVM instance, including unauthorized access to sensitive data and disruption of services.

Technical details

This is a remote code execution vulnerability in the Oracle GraalVM compiler component, accessible via HTTP without authentication. The vulnerability is difficult to exploit but has high impact, allowing an attacker with network access to compromise confidentiality, integrity, and availability. Successful exploitation results in complete takeover of the affected GraalVM instance. The vulnerability affects GraalVM version 25.0.4.1 and likely other versions in that release line. No information about available patches is currently available from Oracle due to resource constraints.

Affected products

  • Oracle GraalVM 25.0.4.1

Timeline

  • 2026-09-15: disclosed

References

Related threats