CVE-2026-87288
nicheUnauthenticated Takeover Flaw in Oracle GraalVM 25.0.4.1 Compiler
CVE-2026-87288 is a difficult-to-exploit vulnerability in the Compiler component of Oracle GraalVM (Oracle Java SE), affecting only version 25.0.4.1. An unauthenticated remote attacker with network access via HTTP can trigger the flaw to compromise the GraalVM installation, and successful attacks can result in a complete takeover with high impacts on confidentiality, integrity, and availability. The CVSS 3.1 base score is 8.1 (high), but the high attack-complexity rating (AC:H) means reliable exploitation is challenging and likely requires timing, luck, or target-specific conditions. Organizations running GraalVM-based services, native-image builds, or polyglot runtimes on the affected version that are reachable over HTTP are exposed. No public proof-of-concept is known, there is no evidence of in-the-wild exploitation, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Upgrade Oracle GraalVM 25.0.4.1 to the version fixed in the corresponding Oracle Critical Patch Update as soon as it is available. Until patched, restrict HTTP and network access to GraalVM hosts (development machines, CI runners, and servers running GraalVM-based applications) to trusted sources only. Review logs on affected hosts for unexplained compiler activity or anomalous process behavior indicative of post-compromise behavior.
| Oracle GraalVM (Oracle Java SE) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.