Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java SE: 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Install component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition allows an attacker with local logon rights to gain full control of the affected system. The vulnerability is a form of improper access control (CWE‑284) and gives the attacker complete confidentiality, integrity, and availability impact for the software stack.

Affected Systems

Oracle Java SE versions 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK versions 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition 21.3.18 are affected. All other product versions are not listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 7.8 indicates a high‑severity vulnerability with local access, low attack complexity, and local privilege requirement. The EPSS score of <1% suggests that exploitation is unlikely at present, and the vulnerability has not entered the CISA KEV catalog. Nonetheless, an attacker who already possesses a logon session can exploit the flaw freely, achieving full takeover of the impacted Oracle Java or GraalVM installation.

Generated by OpenCVE AI on August 4, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security update that includes the fix for CVE‑2026‑62574 to all affected Oracle Java SE releases (8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1).
  • Apply the corresponding update to Oracle GraalVM for JDK (17.0.19 and 21.0.11).
  • Apply the update to Oracle GraalVM Enterprise Edition (21.3.18).

Generated by OpenCVE AI on August 4, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local Logon Exploit Enables Full System Compromise in Oracle Java and GraalVM

Sun, 02 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Java SE and GraalVM Install Component Exploitable for Local Compromise

Thu, 30 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Java SE and GraalVM Install Component Exploitable for Local Compromise

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Attack Enables Complete Takeover of Oracle Java and GraalVM

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Attack Enables Complete Takeover of Oracle Java and GraalVM

Thu, 23 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle graalvm Enterprise Edition
Vendors & Products Oracle graalvm Enterprise Edition

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java SE: 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
CPEs cpe:2.3:a:oracle:graalvm:21.3.18:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:17.0.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:graalvm_for_jdk:21.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:11.0.31:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:17.0.19:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:21.0.11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:25.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:26.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle graalvm
Oracle graalvm For Jdk
Oracle java Se
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Graalvm Graalvm Enterprise Edition Graalvm For Jdk Java Se
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:49.775Z

Reserved: 2026-07-14T14:54:48.742Z

Link: CVE-2026-62574

cve-icon Vulnrichment

Updated: 2026-07-22T13:09:15.585Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses