CVE-2026-46917
CVE-2026-46917 is a medium-severity vulnerability in Oracle Graalvm with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 0% (22nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-284
- Affected product: Oracle Graalvm
- Published:
- Last modified:
Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
Frequently asked questions
- What is CVE-2026-46917?
- Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
- How severe is CVE-2026-46917?
- CVE-2026-46917 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-46917 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (22nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-46917?
- CVE-2026-46917 primarily affects Oracle Graalvm. In total, 13 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-46917?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-46917 published?
- CVE-2026-46917 was published on 2026-07-21 and last updated on 2026-08-03.
References
Affected products (13)
- cpe:2.3:a:oracle:graalvm:21.3.18:*:*:*:enterprise:*:*:*
- cpe:2.3:a:oracle:graalvm_for_jdk:17.0.19:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:graalvm_for_jdk:21.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:11.0.31:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:17.0.19:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:21.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:25.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jre:26.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:11.0.31:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:17.0.19:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:21.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:25.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:jdk:26.0.1:*:*:*:*:*:*:*
More vulnerabilities in Oracle Graalvm
- CVE-2021-22931 — Critical (CVSS 9.8): Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to…
- CVE-2021-29921 — Critical (CVSS 9.8): In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string.…
- CVE-2019-15606 — Critical (CVSS 9.8): Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on…
- CVE-2019-15605 — Critical (CVSS 9.8): HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
- CVE-2019-17560 — Critical (CVSS 9.1): The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads.…
- CVE-2023-41993 — High (CVSS 8.8): The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead…
All CVEs affecting Oracle Graalvm →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.
- CVE-2026-20315 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering…
- CVE-2026-70921 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-66803 — Critical (CVSS 10.0): Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-58630 — Critical (CVSS 10.0): Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-60358 — Critical (CVSS 10.0): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).…
Browse all CWE-284 (Improper Access Control) vulnerabilities →