Description
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability resides in the Compiler component of Oracle GraalVM and allows an attacker to compromise the system without authentication, leading to a full takeover. The flaw permits modification of confidentiality, integrity, and availability, as reflected in the CVSS vector. The description clearly states that successful exploitation can result in complete control over the GraalVM platform. The likely attack on the mention of "network access via HTTP," an unauthenticated HTTP request to the vulnerable service is inferred as the means of exploitation.

Affected Systems

Oracle GraalVM 25.0.4.1 is the only documented affected version. Administrators should verify whether their installations match this version and apply any available updates thereafter.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity with full impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that, as of the most recent data, the probability of exploitation is low, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, because the flaw permits a remote takeover, the potential impact remains significant, warranting timely remediation.

Generated by OpenCVE AI on September 17, 2026 at 06:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle GraalVM to a version that does not contain the vulnerable Compiler component or apply the vendor-provided patch.
  • Restrict network exposure of the GraalVM HTTP interface so that only trusted hosts can reach it, effectively limiting unauthenticated external access.
  • If a direct patch is not immediately available, monitor the service for anomalous activity and consider disabling or isolating the compiler feature responsible for the vulnerability until a proper fix can be deployed.

Generated by OpenCVE AI on September 17, 2026 at 06:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title GraalVM Compiler Component Vulnerability Allows Unauthenticated Remote Takeover via HTTP

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle graalvm
CPEs cpe:2.3:a:oracle:graalvm:25.0.4.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle graalvm
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T16:31:11.561Z

Reserved: 2026-09-08T21:49:12.409Z

Link: CVE-2026-87288

cve-icon Vulnrichment

Updated: 2026-09-16T14:53:43.347Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:18.790

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-87288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T06:30:09Z

Weaknesses