ZeroHour

CVE-2026-83408

moderate

Unauthenticated Takeover Flaw in Oracle GraalVM Compiler Component

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-83408 is a difficult-to-exploit vulnerability in the Compiler component of Oracle GraalVM for JDK and Oracle GraalVM that allows an unauthenticated attacker with network access via HTTP to compromise the affected installation. A successful attack can result in a complete takeover of GraalVM, with high impacts on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). Affected releases are Oracle GraalVM for JDK 17 version 23.0.13.1, Oracle GraalVM for JDK 21 version 23.1.12.1, and Oracle GraalVM version 25.0.4.1. The high attack complexity means reliable exploitation is likely to require race conditions or specialized conditions, lowering practical risk somewhat. There is no known public proof of concept, the issue is not on the CISA KEV list, and no exploitation in the wild has been reported.

What to do: Upgrade affected Oracle GraalVM installations (GraalVM for JDK 17, JDK 21, and GraalVM 25) to the fixed releases provided in Oracle's latest Critical Patch Update. Restrict network and HTTP access to systems and services running GraalVM so they are not reachable by untrusted clients. Check build pipelines, CI images, and native-image runtimes for the three listed versions and verify no anomalous process activity has occurred on hosts that were exposed.

Affected
Oracle GraalVM for JDK 1723.0.13.1
Oracle GraalVM for JDK 2123.1.12.1
Oracle GraalVM25.0.4.1
Estimated exposure
moderatetens of thousands of installations (developer workstations and servers running GraalVM-based runtimes) — GraalVM is a specialized JDK distribution used primarily by developers and for native-image/AOT deployments rather than a broadly internet-exposed appliance, and only three specific recent release versions are affected, so the vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK, Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK, Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.