Impact
A flaw in the Install component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition allows an attacker with local logon rights to gain full control of the affected system. The vulnerability is a form of improper access control (CWE‑284) and gives the attacker complete confidentiality, integrity, and availability impact for the software stack.
Affected Systems
Oracle Java SE versions 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK versions 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition 21.3.18 are affected. All other product versions are not listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.8 indicates a high‑severity vulnerability with local access, low attack complexity, and local privilege requirement. The EPSS score of <1% suggests that exploitation is unlikely at present, and the vulnerability has not entered the CISA KEV catalog. Nonetheless, an attacker who already possesses a logon session can exploit the flaw freely, achieving full takeover of the impacted Oracle Java or GraalVM installation.
OpenCVE Enrichment