ZeroHour

CVE-2026-87286

niche

Hard-to-Exploit Unauthenticated Takeover Flaw in Oracle GraalVM 25.0.4.1 Compiler

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87286 is a high-severity (CVSS 8.1) vulnerability in the Compiler component of Oracle GraalVM for Oracle Java SE, affecting only version 25.0.4.1. An unauthenticated remote attacker with network access via HTTP can trigger the flaw, and a successful exploit can result in a complete takeover of Oracle GraalVM, with high impacts on confidentiality, integrity, and availability. Oracle rates the vulnerability as difficult to exploit (Attack Complexity: High), meaning reliable exploitation requires specialized conditions or race-like circumstances rather than a trivial request. The exposure is limited to systems actually running the specific GraalVM 25.0.4.1 release, typically developer workstations, CI/CD build infrastructure, and applications deployed on GraalVM that serve HTTP traffic. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and there are no reports of in-the-wild exploitation at this time.

What to do: Upgrade Oracle GraalVM from 25.0.4.1 to the fixed release provided in Oracle's Critical Patch Update covering this CVE. Audit build pipelines, developer environments, and production services for any system reporting GraalVM 25.0.4.1, and restrict network/HTTP reachability to GraalVM-based services until patched. Monitor Oracle's advisory for the fixed version number and any updated exploitation guidance.

Affected
Oracle GraalVM (Oracle Java SE), Compiler component
Estimated exposure
nichelikely tens of thousands of GraalVM installations at most (developer machines, CI/build servers, and HTTP-serving apps on GraalVM 25.0.4.1); exact count unknown — GraalVM is a developer-focused Java runtime/toolchain rather than a widely deployed internet-facing service, only the single 25.0.4.1 release is affected, and no public scan or install-count data exists for GraalVM deployments, so this is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.