Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-08-18
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits an unauthenticated attacker with network access to supply crafted data to certain APIs in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, resulting in unauthorized read access to a subset of accessible data. The weakness involves insufficient protection of sensitive information, a classic information‑exposure flaw (CWE‑200). The impact is limited to confidentiality without affecting integrity or availability.

Affected Systems

Affected vendors include Oracle Corporation, with products Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. The specific vulnerable releases are: Oracle Java SE 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK 17.0.20 and 21.0.12; and Oracle GraalVM Enterprise Edition 21.3.19.

Risk and Exploitability

The base CVSS score is 3.7, indicating a low severity but still noteworthy confidentiality impact. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based, via multiple protocols that allow the attacker to supply malicious input to the affected APIs; an unauthenticated attacker can exploit the flaw without needing any privileged access or application‑specific features such as Java Web Start or applets.

Generated by OpenCVE AI on August 18, 2026 at 23:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Oracle Java SE update that addresses CVE-2026-60589 for all affected versions (8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2).
  • Apply the most recent Oracle GraalVM for JDK release that contains the fix (versions 17.0.20 and 21.0.12) and update Oracle GraalVM Enterprise Edition to at least 21.3.19 or later.
  • Restrict network access to the vulnerable APIs by configuring firewalls or network segmentation to limit exposure only to trusted hosts and services.

Generated by OpenCVE AI on August 18, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via API in Oracle Java SE and GraalVM
Weaknesses CWE-200

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
CPEs cpe:2.3:a:oracle:graalvm:21.3.19:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:17.0.20:*:*:*:*:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:21.0.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:11.0.32:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:17.0.20:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:21.0.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:25.0.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:26.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u501:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Graalvm Graalvm For Jdk Java Se
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:58:55.601Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:38.247

Modified: 2026-08-18T21:16:38.247

Link: CVE-2026-60589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T23:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor