Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the ImageIO component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition permits an unauthenticated attacker with network access to perform unauthorized update, insert, or delete operations against data accessible to the Java or GraalVM runtime. The flaw can be triggered through image processing APIs, for example from a web service that supplies JPEG data to the application, and also applies to sandboxed client deployments that load untrusted code. The impact is strictly on integrity, resulting in potential data modification without disabling services or escalating privileges. This vulnerability involves both unauthorized access control (CWE‑284) and memory corruption via out‑of‑bounds writes (CWE‑787).

Affected Systems

Oracle GraalVM Enterprise Edition 21.3.18, Oracle GraalVM for JDK 17.0.19 and 21.0.11, and Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1 are affected.

Risk and Exploitability

The CVSS v3.1 base score of 3.7 combined with an EPSS score of less than 1% indicates low severity but a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack can be carried out remotely via network protocols; no authentication or elevated privileges are required, so an attacker only needs network reach to the vulnerable system to exploit the flaw.

Generated by OpenCVE AI on August 4, 2026 at 05:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Java SE, Oracle GraalVM for JDK, or Oracle GraalVM Enterprise Edition to the latest patched release that removes the ImageIO issue.
  • If an upgrade is not possible, limit ImageIO JPEG decoding to trusted data sources only or disable JPEG handling in the affected applications.
  • Implement strict input validation or sanitization for all JPEG files before passing them to ImageIO APIs.

Generated by OpenCVE AI on August 4, 2026 at 05:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4702-1 openjdk-11 security update
Debian DLA Debian DLA DLA-4703-1 openjdk-17 security update
Debian DSA Debian DSA DSA-6425-1 openjdk-21 security update
History

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle graalvm Enterprise Edition
Vendors & Products Oracle graalvm Enterprise Edition

Wed, 22 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title openjdk: OpenJDK: Enhance JPEG handling (Oracle CPU 2026-07)
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Low


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
CPEs cpe:2.3:a:oracle:graalvm:21.3.18:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:17.0.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:21.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:11.0.31:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:17.0.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:21.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:25.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:26.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u491:*:*:*:enterprise_performance:*:*:*
Vendors & Products Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Graalvm Graalvm Enterprise Edition Graalvm For Jdk Java Se
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T14:58:56.335Z

Reserved: 2026-05-18T15:55:10.316Z

Link: CVE-2026-47010

cve-icon Vulnrichment

Updated: 2026-07-23T14:58:47.945Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-21T20:00:00Z

Links: CVE-2026-47010 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses