CVE-2026-22013General(oracle / graalvm)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • graalvm
  • graalvm_for_jdk
  • jdk
  • jre

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
graalvmgraalvm_for_jdkjdkjre

7 versions affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-26: 2Mentions · 2026-04-29: 1Technical Details · 2026-04-26: 104-2604-29
Signal classification1 categories
General
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-262
General2
2026-04-291
General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-22013 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that a… https://www.cve.org/CVERecord?id=CVE-2026-22013

    Post summary

    The text lists CVE‑2026‑22013 as a vulnerability in the JGSS component of Oracle Java SE, but provides no further technical or exploit details.

    00010236
    57.3K followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 30% of vulnerabilities from past week, CVE-2026-22013 has 7 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post notes that CVE-2026-22013 has attracted many articles, but it offers no additional technical detail, PoC, or evidence of exploitation.

    0000034
    69 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-22013 Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that a… https://www.cve.org/CVERecord?id=CVE-2026-22013 ----- Traducción: CVE-2026-22013 Vul… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑22013 and links to its CVE.org record, but provides no further information on exploitation, patches, or technical details.

    0000044
    72 followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclegraalvm21.3.17--
Apporaclegraalvm_for_jdk17.0.18--
Apporaclegraalvm_for_jdk21.0.10--
Apporaclejdk1.8.0--
Apporaclejdk1.8.0--
Apporaclejdk1.8.0--
Apporaclejdk11.0.30--
Apporaclejdk17.0.18--
Apporaclejdk21.0.10--
Apporaclejdk25.0.2--
Apporaclejdk26--
Apporaclejre1.8.0--
Apporaclejre1.8.0--
Apporaclejre1.8.0--
Apporaclejre11.0.30--
Apporaclejre17.0.18--
Apporaclejre21.0.10--
Apporaclejre25.0.2--
Apporaclejre26--

Explore more