CVE-2026-87287
nicheUnauthenticated HTTP Takeover Flaw in Oracle GraalVM 25.0.4.1 Compiler
Oracle GraalVM 25.0.4.1 (part of Oracle Java SE) contains a vulnerability in its Compiler component that allows an unauthenticated remote attacker with network access via HTTP to compromise the GraalVM installation. Oracle rates the vulnerability as difficult to exploit (Attack Complexity: High), but a successful attack can result in a complete takeover of GraalVM with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.1). Only the specific version Oracle GraalVM 25.0.4.1 is listed as affected. There is no known public proof-of-concept, the flaw is not on the CISA Known Exploited Vulnerabilities catalog, and no exploitation in the wild has been reported. Because exploitation depends on HTTP-reachable GraalVM runtimes, deployments that do not expose GraalVM-based services to untrusted networks are at substantially lower risk.
What to do: Upgrade Oracle GraalVM from 25.0.4.1 to the fixed release provided in Oracle's latest Critical Patch Update, since only that version is listed as affected. Restrict HTTP/network access to GraalVM-based services so they are not reachable by untrusted clients, which also mitigates the high attack-complexity exploitation path. Audit logs on GraalVM 25.0.4.1 hosts for unexplained process or compiler activity until the upgrade is complete.
| Oracle GraalVM (Oracle Java SE), Compiler component | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.