
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21925 is a vulnerability in the RMI (Remote Method Invocation) component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition that allows unauthenticated remote attackers to bypass security controls and perform unauthorized read and write operations on accessible data. The flaw was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update. Affected versions include Oracle Java SE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1; Oracle GraalVM for JDK 17.0.17 and 21.0.9; and Oracle GraalVM Enterprise Edition 21.3.16. It carries a CVSS v3.1 base score of 4.8 (Medium) (Oracle CPU Jan 2026, Red Hat Bugzilla).
The root cause is classified as CWE-322 (Key Exchange without Entity Authentication). Specifically, a client RMI TCP endpoint connects to a remote host without setting an endpoint identification algorithm, which fails to validate the server's identity during the TLS handshake and enables man-in-the-middle (MITM) attacks (Red Hat Bugzilla). The vulnerability is exploitable over a network via multiple protocols without requiring authentication or user interaction, though it is rated as "difficult to exploit" due to the high attack complexity required to position an attacker in a MITM role. The vulnerability also applies to Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load untrusted code from the internet (Oracle CPU Jan 2026). Upstream fix commits are available for OpenJDK 8, 11, 17, 21, and 25 (Red Hat Bugzilla).
Successful exploitation can result in unauthorized read access to a subset of Oracle Java SE, GraalVM for JDK, and GraalVM Enterprise Edition accessible data, as well as unauthorized update, insert, or delete operations on that data. There is no availability impact. The vulnerability affects confidentiality and integrity at a low level within the scope of the affected Java runtime environment, and does not provide a path to full system compromise or significant lateral movement on its own (Oracle CPU Jan 2026).
Oracle has released fixed versions addressing this vulnerability: Oracle Java SE 8u481, 11.0.30, 17.0.18, 21.0.10, and 25.0.2 (Red Hat Bugzilla). Red Hat has issued patches via RHSA-2026:0931 (RHEL 7 ELS) and RHSA-2026:4832 (RHEL 8), among other errata. IBM has released fixes for affected products including IBM i, IBM MQ, IBM Cloud Pak for Business Automation, IBM Sterling Transformation Extender, and others (IBM i Advisory). Organizations should upgrade to the patched Java SE or GraalVM versions as soon as possible. As a temporary measure, restricting network access to RMI/JMX endpoints and enforcing strict firewall rules to prevent unauthorized MITM positioning can reduce risk (Oracle CPU Jan 2026).
The vulnerability received routine coverage across Linux distribution security channels, with advisories issued by Red Hat, Debian, Ubuntu, SUSE, AlmaLinux, Rocky Linux, Amazon Linux, and Mageia shortly after Oracle's January 2026 CPU disclosure. IBM issued multiple security bulletins for its affected product portfolio. The OpenJDK project published its own advisory at openjdk.org. No notable independent researcher commentary or significant social media discussion has been identified beyond standard patch notification channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."