Description
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution and potential takeover of Oracle GraalVM
Action: Patch Immediately
AI Analysis

Impact

A vulnerability exists in the Compiler component of Oracle GraalVM that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation can result in full control over the GraalVM instance, impacting confidentiality, integrity, and availability. The CVSS v3.1 score of 8.1 reflects a high severity attack that requires high attack complexity but no privileged access or user interaction.

Affected Systems

Oracle GraalVM, version 25.0.4.1, is the affected edition. The vulnerability is specific to the Compiler component of this product. No other versions or sub‑products are listed as impacted.

Risk and Exploitability

The CVSS base score indicates a significant risk, yet the EPSS score of probability of exploitation at this time. The vulnerability is not present in CISA’s KEV catalog. The likely attack vector is a remote unauthenticated HTTP connection to the GraalVM service, and because the vulnerability is described as difficult to exploit, a skilled attacker would need to precisely target the affected compiler functionality. Due to the potential for full system takeover, organizations should treat this as a high-priority risk.

Generated by OpenCVE AI on September 17, 2026 at 05:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle GraalVM to a version that addresses the Compiler component vulnerability.
  • If an upgrade is not immediately possible, restrict network configuring firewall rules or an authentication proxy to block unauthenticated traffic.
  • Implement monitoring for abnormal HTTP requests or compiler activity that could indicate exploitation attempts.

Generated by OpenCVE AI on September 17, 2026 at 05:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTP Access in Oracle GraalVM 25.0.4.1
Weaknesses CWE-284

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle graalvm
CPEs cpe:2.3:a:oracle:graalvm:25.0.4.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle graalvm
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-15T19:56:02.435Z

Reserved: 2026-09-08T21:49:12.409Z

Link: CVE-2026-87286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:18.560

Modified: 2026-09-16T19:42:12.090

Link: CVE-2026-87286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:00:09Z

Weaknesses