CVE-2026-21925
Amazon Corretto JDK vulnerability analysis and mitigation

Overview

CVE-2026-21925 is a vulnerability in the RMI (Remote Method Invocation) component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition that allows unauthenticated remote attackers to bypass security controls and perform unauthorized read and write operations on accessible data. The flaw was disclosed on January 20, 2026, as part of Oracle's January 2026 Critical Patch Update. Affected versions include Oracle Java SE 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1; Oracle GraalVM for JDK 17.0.17 and 21.0.9; and Oracle GraalVM Enterprise Edition 21.3.16. It carries a CVSS v3.1 base score of 4.8 (Medium) (Oracle CPU Jan 2026, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-322 (Key Exchange without Entity Authentication). Specifically, a client RMI TCP endpoint connects to a remote host without setting an endpoint identification algorithm, which fails to validate the server's identity during the TLS handshake and enables man-in-the-middle (MITM) attacks (Red Hat Bugzilla). The vulnerability is exploitable over a network via multiple protocols without requiring authentication or user interaction, though it is rated as "difficult to exploit" due to the high attack complexity required to position an attacker in a MITM role. The vulnerability also applies to Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load untrusted code from the internet (Oracle CPU Jan 2026). Upstream fix commits are available for OpenJDK 8, 11, 17, 21, and 25 (Red Hat Bugzilla).

Impact

Successful exploitation can result in unauthorized read access to a subset of Oracle Java SE, GraalVM for JDK, and GraalVM Enterprise Edition accessible data, as well as unauthorized update, insert, or delete operations on that data. There is no availability impact. The vulnerability affects confidentiality and integrity at a low level within the scope of the affected Java runtime environment, and does not provide a path to full system compromise or significant lateral movement on its own (Oracle CPU Jan 2026).

Exploitation steps

  1. Reconnaissance: Identify target systems running vulnerable versions of Oracle Java SE (8u471, 11.0.29, 17.0.17, 21.0.9, 25.0.1), GraalVM for JDK, or GraalVM Enterprise Edition that expose RMI or JMX endpoints over the network.
  2. Network Positioning: Gain a man-in-the-middle position on the network path between the Java client and the RMI/JMX server (e.g., via ARP spoofing, DNS poisoning, or rogue network device).
  3. Intercept RMI Connection: Intercept the RMI TCP connection initiated by the client. Because the client does not set an endpoint identification algorithm, it does not validate the server's TLS certificate identity, allowing the attacker to present a fraudulent certificate.
  4. Impersonate Server: Present a self-signed or attacker-controlled certificate to the client, which accepts it without proper hostname/identity verification.
  5. Data Manipulation: Read, modify, insert, or delete data exchanged over the RMI/JMX channel between the client and the legitimate server, achieving unauthorized access to accessible data (Red Hat Bugzilla, Oracle CPU Jan 2026).

Indicators of compromise

  • Network: Unexpected ARP or DNS anomalies on network segments hosting Java RMI/JMX services; unusual TLS certificate changes observed on RMI/JMX ports (default: 1099 for RMI, configurable for JMX).
  • Logs: Java application logs showing unexpected RMI connection sources or certificate-related warnings; JMX connection attempts from unexpected IP addresses.
  • Process: Java processes initiating RMI/JMX connections to unexpected or newly observed remote endpoints.

Mitigation and workarounds

Oracle has released fixed versions addressing this vulnerability: Oracle Java SE 8u481, 11.0.30, 17.0.18, 21.0.10, and 25.0.2 (Red Hat Bugzilla). Red Hat has issued patches via RHSA-2026:0931 (RHEL 7 ELS) and RHSA-2026:4832 (RHEL 8), among other errata. IBM has released fixes for affected products including IBM i, IBM MQ, IBM Cloud Pak for Business Automation, IBM Sterling Transformation Extender, and others (IBM i Advisory). Organizations should upgrade to the patched Java SE or GraalVM versions as soon as possible. As a temporary measure, restricting network access to RMI/JMX endpoints and enforcing strict firewall rules to prevent unauthorized MITM positioning can reduce risk (Oracle CPU Jan 2026).

Community reactions

The vulnerability received routine coverage across Linux distribution security channels, with advisories issued by Red Hat, Debian, Ubuntu, SUSE, AlmaLinux, Rocky Linux, Amazon Linux, and Mageia shortly after Oracle's January 2026 CPU disclosure. IBM issued multiple security bulletins for its affected product portfolio. The OpenJDK project published its own advisory at openjdk.org. No notable independent researcher commentary or significant social media discussion has been identified beyond standard patch notification channels.

Additional resources


SourceThis report was generated using AI

Related Amazon Corretto JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34282HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • cpe:2.3:a:oracle:graalvm:*:*:*:*:enterprise:*:*:*
NoYesApr 21, 2026
CVE-2026-22016HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-openjdk-headless
NoYesApr 21, 2026
CVE-2026-22021MEDIUM5.3
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openj9-src
NoYesApr 21, 2026
CVE-2026-22018LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openjdk-devel-slowdebug-debuginfo
NoYesApr 21, 2026
CVE-2026-34268LOW2.9
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.8.0-openjdk-fastdebug-debuginfo
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management