Description
Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Published: 2026-07-21
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability affects the Java Secure Socket Extension (JSSE) component of Oracle Java SE. An unauthenticated attacker with network access can supply crafted data to exposed TLS APIs, enabling unauthorized creation, deletion, or modification of data that the Java runtime can access. The issue does not compromise confidentiality or availability, but it allows an attacker to alter critical information, thereby violating integrity. The attack requires TLS communication with the vulnerable service and does not rely on malicious Java applets or Web Start applications.

Affected Systems

Affected products include Oracle Java SE 8 (update 491 and performance build), 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1. These versions are listed as vulnerable in the CNA advisory.

Risk and Exploitability

The CVSS v3.1 base score is 5.9, indicating a moderate risk with an impact focused on integrity. The EPSS score is less than 1%, suggesting low probability of exploitation, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires network access over TLS and an ability to invoke specific JSSE APIs. The attacker does not need prior authentication or privileged access, but the exploitation path has high complexity due to the requirement of supplying precise data to the vulnerable interfaces.

Generated by OpenCVE AI on August 4, 2026 at 17:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Java SE to the newest patch release that addresses this JSSE issue (e.g., 8u492, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2).
  • For systems using Oracle GraalVM, install the latest JDK or Enterprise Edition release that includes the JSSE fix.
  • If an immediate update is not possible, restrict TLS connections to the service, disabling or hardening the exposed JSSE APIs to prevent unauthenticated data submission.

Generated by OpenCVE AI on August 4, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4702-1 openjdk-11 security update
Debian DLA Debian DLA DLA-4703-1 openjdk-17 security update
Debian DSA Debian DSA DSA-6425-1 openjdk-21 security update
History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title openjdk: Enhance TLS certificate handling
Weaknesses CWE-295
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
First Time appeared Oracle
Oracle java Se
CPEs cpe:2.3:a:oracle:java_se:11.0.31:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:17.0.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:21.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:25.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:26.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u491:*:*:*:enterprise_performance:*:*:*
Vendors & Products Oracle
Oracle java Se
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:17:46.291Z

Reserved: 2026-05-18T15:55:10.314Z

Link: CVE-2026-46968

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:45.316Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:34:00Z

Links: CVE-2026-46968 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-295

    Improper Certificate Validation