CVE-2026-83408: Code Injection
Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK, Oracle GraalVM. Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK, Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The affected supported releases are Oracle GraalVM for JDK 17 version 23.0.13.1, Oracle GraalVM for JDK 21 version 23.1.12.1, and Oracle GraalVM version 25.0.4.1. Exposure requires that an unauthenticated attacker can reach the affected GraalVM environment over HTTP.
Does exploitation require credentials or user interaction?
No. The vulnerability is described as exploitable by an unauthenticated attacker with network access via HTTP, and the CVSS vector indicates no privileges and no user interaction are required. Exploitation is nonetheless rated difficult, with high attack complexity.
What could a successful attack allow?
A successful attack can result in takeover of the affected Oracle GraalVM for JDK or Oracle GraalVM product. Confidentiality, integrity, and availability impacts are all rated high.
How can I determine whether an environment is affected?
Identify whether the deployment uses Oracle GraalVM for JDK 17 at 23.0.13.1, Oracle GraalVM for JDK 21 at 23.1.12.1, or Oracle GraalVM at 25.0.4.1. Also determine whether the environment is reachable by unauthenticated users over HTTP, as that is the stated attack path.