Description
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Oracle GraalVM compiler component enables an attacker with network access over HTTP to exploit Oracle GraalVM without authentication. The vulnerability is rooted in an lack of proper authorization checks, classified as CWE-284, and can lead to a full compromise of the GraalVM instance, affecting confidentiality, integrity, and availability.

Affected Systems

Oracle GraalVM, version 25.0.4.1. No other versions are listed in the advisory; the vulnerability does not affect earlier or later releases unless explicitly stated by Oracle.

Risk and Exploitability

The CVSS v3.1 base score is 8.1, indicating high severity. The EPSS score is below 1%, suggesting that while exploitation is technically feasible, it is unlikely to be widely deployed. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to send malicious HTTP requests to the GraalVM instance; no prior authentication or elevated privileges are required, but the attack complexity is high due to the need to trigger the specific compiler behavior.

Generated by OpenCVE AI on September 17, 2026 at 06:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle GraalVM 25.0.4.1 security patch or upgrade to a later patched release if available
  • Block or restrict inbound HTTP traffic to the GraalVM server to the minimum required set of clients
  • If patching cannot be applied immediately, disable or remove the vulnerable compiler component from the GraalVM installation
  • Observe and log all incoming HTTP requests to the GraalVM service for anomalous activity

Generated by OpenCVE AI on September 17, 2026 at 06:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit in Oracle GraalVM 25.0.4.1 Allowing Full System Takeover

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle graalvm
CPEs cpe:2.3:a:oracle:graalvm:25.0.4.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle graalvm
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:31:18.114Z

Reserved: 2026-09-08T21:49:12.409Z

Link: CVE-2026-87287

cve-icon Vulnrichment

Updated: 2026-09-16T14:53:40.607Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:18.680

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-87287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:30:09Z

Weaknesses