CVE-2026-87286
nicheHard-to-Exploit Unauthenticated Takeover Flaw in Oracle GraalVM 25.0.4.1 Compiler
CVE-2026-87286 is a high-severity (CVSS 8.1) vulnerability in the Compiler component of Oracle GraalVM for Oracle Java SE, affecting only version 25.0.4.1. An unauthenticated remote attacker with network access via HTTP can trigger the flaw, and a successful exploit can result in a complete takeover of Oracle GraalVM, with high impacts on confidentiality, integrity, and availability. Oracle rates the vulnerability as difficult to exploit (Attack Complexity: High), meaning reliable exploitation requires specialized conditions or race-like circumstances rather than a trivial request. The exposure is limited to systems actually running the specific GraalVM 25.0.4.1 release, typically developer workstations, CI/CD build infrastructure, and applications deployed on GraalVM that serve HTTP traffic. No public proof of concept is known, the flaw is not on the CISA Known Exploited Vulnerabilities list, and there are no reports of in-the-wild exploitation at this time.
What to do: Upgrade Oracle GraalVM from 25.0.4.1 to the fixed release provided in Oracle's Critical Patch Update covering this CVE. Audit build pipelines, developer environments, and production services for any system reporting GraalVM 25.0.4.1, and restrict network/HTTP reachability to GraalVM-based services until patched. Monitor Oracle's advisory for the fixed version number and any updated exploitation guidance.
| Oracle GraalVM (Oracle Java SE), Compiler component | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.