Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper validation of certificates during security checks (CWE‑295) combined with an access control weakness (CWE‑284) allows an attacker to send specially crafted data to Java security APIs and bypass certificate verification, enabling privileged operations. The likely attack vector is inferred as remote network access via exposed APIs, as the description mentions network reachability is sufficient for exploitation and no authentication is required.

Affected Systems

Affected products include Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. Vulnerable versions are 8u491 and 8u491‑perf for Java SE, 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1 for Java SE, 17.0.19 and 21.0.11 for GraalVM for JDK, and 21.3.18 for GraalVM Enterprise Edition.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates moderate severity with low confidentiality and integrity impact. The EPSS score of less than 1 % suggests that exploitation is currently unlikely in the wild, yet the vulnerability can be triggered from any network‑reachable endpoint that exposes the compromised APIs without authentication or elevated privileges. If exploited, an attacker could modify or exfiltrate data stored by the affected Java runtime. The risk profile remains moderate, so unpatched systems should prioritize remediation.

Generated by OpenCVE AI on August 2, 2026 at 23:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Java SE, Oracle GraalVM for JDK, or Oracle GraalVM Enterprise Edition to the latest patched versions provided by Oracle
  • Restrict network exposure of the vulnerable APIs using firewalls or network segmentation, and/or disable any exposed security APIs until a patch is applied
  • Enforce strict certificate validation policies or use a hardened runtime configuration that rejects untrusted certificates to mitigate the certificate‑checking flaw

Generated by OpenCVE AI on August 2, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4702-1 openjdk-11 security update
Debian DLA Debian DLA DLA-4703-1 openjdk-17 security update
Debian DSA Debian DSA DSA-6425-1 openjdk-21 security update
History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle graalvm Enterprise Edition
Vendors & Products Oracle graalvm Enterprise Edition

Wed, 22 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title openjdk: OpenJDK: Improve certification checking (Oracle CPU 2026-07)
Weaknesses CWE-295
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
CPEs cpe:2.3:a:oracle:graalvm:21.3.18:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:17.0.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:21.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:11.0.31:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:17.0.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:21.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:25.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:26.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u491:*:*:*:enterprise_performance:*:*:*
Vendors & Products Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Graalvm Graalvm Enterprise Edition Graalvm For Jdk Java Se
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:24:57.217Z

Reserved: 2026-07-08T15:51:40.514Z

Link: CVE-2026-60147

cve-icon Vulnrichment

Updated: 2026-07-23T15:24:46.856Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T20:00:00Z

Links: CVE-2026-60147 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:00:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-295

    Improper Certificate Validation