CVE-2026-83408
moderateUnauthenticated Takeover Flaw in Oracle GraalVM Compiler Component
CVE-2026-83408 is a difficult-to-exploit vulnerability in the Compiler component of Oracle GraalVM for JDK and Oracle GraalVM that allows an unauthenticated attacker with network access via HTTP to compromise the affected installation. A successful attack can result in a complete takeover of GraalVM, with high impacts on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). Affected releases are Oracle GraalVM for JDK 17 version 23.0.13.1, Oracle GraalVM for JDK 21 version 23.1.12.1, and Oracle GraalVM version 25.0.4.1. The high attack complexity means reliable exploitation is likely to require race conditions or specialized conditions, lowering practical risk somewhat. There is no known public proof of concept, the issue is not on the CISA KEV list, and no exploitation in the wild has been reported.
What to do: Upgrade affected Oracle GraalVM installations (GraalVM for JDK 17, JDK 21, and GraalVM 25) to the fixed releases provided in Oracle's latest Critical Patch Update. Restrict network and HTTP access to systems and services running GraalVM so they are not reachable by untrusted clients. Check build pipelines, CI images, and native-image runtimes for the three listed versions and verify no anomalous process activity has occurred on hosts that were exposed.
| Oracle GraalVM for JDK 17 | 23.0.13.1 |
| Oracle GraalVM for JDK 21 | 23.1.12.1 |
| Oracle GraalVM | 25.0.4.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK, Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK, Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.