ZeroHour

CVE-2026-87288

niche

Unauthenticated Takeover Flaw in Oracle GraalVM 25.0.4.1 Compiler

CVSS 3.1
8.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87288 is a difficult-to-exploit vulnerability in the Compiler component of Oracle GraalVM (Oracle Java SE), affecting only version 25.0.4.1. An unauthenticated remote attacker with network access via HTTP can trigger the flaw to compromise the GraalVM installation, and successful attacks can result in a complete takeover with high impacts on confidentiality, integrity, and availability. The CVSS 3.1 base score is 8.1 (high), but the high attack-complexity rating (AC:H) means reliable exploitation is challenging and likely requires timing, luck, or target-specific conditions. Organizations running GraalVM-based services, native-image builds, or polyglot runtimes on the affected version that are reachable over HTTP are exposed. No public proof-of-concept is known, there is no evidence of in-the-wild exploitation, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Upgrade Oracle GraalVM 25.0.4.1 to the version fixed in the corresponding Oracle Critical Patch Update as soon as it is available. Until patched, restrict HTTP and network access to GraalVM hosts (development machines, CI runners, and servers running GraalVM-based applications) to trusted sources only. Review logs on affected hosts for unexplained compiler activity or anomalous process behavior indicative of post-compromise behavior.

Affected
Oracle GraalVM (Oracle Java SE)
Estimated exposure
nicheunknown — plausibly low thousands of deployments, with very few HTTP-exposed instances — GraalVM is a JVM distribution and developer toolchain with no published install counts, and its compiler component is generally not an internet-exposed service, so only development, CI, and server deployments that expose HTTP endpoints to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.