CVE-2026-21932
Amazon Corretto JDK vulnerability analysis and mitigation

Overview

CVE-2026-21932 is an integrity bypass vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting the AWT and JavaFX (Desktop) components, specifically related to improper handling of URIs. Disclosed as part of Oracle's January 2026 Critical Patch Update (CPU), it affects Oracle Java SE versions 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1; Oracle GraalVM for JDK 17.0.17 and 21.0.9; and Oracle GraalVM Enterprise Edition 21.3.16. The vulnerability was reported to Oracle by Mingijung of WebSec Lab (Oracle CPU Jan 2026). It carries a CVSS v3.1 base score of 7.4 (High) (Red Hat Bugzilla, Oracle CPU Jan 2026).

Technical details

The root cause is classified as CWE-1287 (Improper Validation of Specified Type of Input), specifically involving improper handling of URIs in the Desktop.browse() method. According to the Red Hat Bugzilla entry, Desktop.browse() will execute a program if the URI is a filename, whereas the documentation specifies that the default browser should be used to open the URI — representing a type confusion/validation bypass (Red Hat Bugzilla). The attack vector is network-based, requires no privileges, but does require user interaction (e.g., a user must open a malicious Java Web Start application or sandboxed applet that loads untrusted code). The vulnerability has a changed scope, meaning successful exploitation can impact resources beyond the vulnerable component itself. Upstream fix commits are available for OpenJDK 8, 11, 17, 21, and 25 (Red Hat Bugzilla).

Impact

Successful exploitation allows an unauthenticated remote attacker to bypass Java security controls and perform unauthorized creation, deletion, or modification of critical or all accessible data within the Java environment, with no confidentiality or availability impact. The changed scope indicates that attacks may significantly impact additional products or resources beyond the directly vulnerable Java component. This vulnerability specifically affects Java Web Start applications and sandboxed Java applets that load untrusted code; server-side Java deployments running only trusted code are not affected (Oracle CPU Jan 2026, Red Hat Bugzilla).

Mitigation and workarounds

Oracle has released patches for all affected versions as part of the January 2026 Critical Patch Update. Fixed versions include Oracle Java SE 8u481, 11.0.30, 17.0.18, 21.0.10, and 25.0.2 (Red Hat Bugzilla). Downstream vendors including Red Hat (RHSA-2026:0849, RHSA-2026:0900, RHSA-2026:1606), Ubuntu (USN-7995-1, USN-7998-1, USN-8000-1), Debian, SUSE, and Amazon Linux have also released updated packages. IBM has issued advisories for affected products including IBM i, IBM MQ, IBM Business Automation Workflow, IBM Guardium, and others (IBM i Advisory). Organizations should prioritize upgrading to patched Java SE and GraalVM versions; as a temporary measure, restricting execution of untrusted Java Web Start applications and applets can reduce exposure (Oracle CPU Jan 2026).

Community reactions

Oracle credited Mingijung of WebSec Lab for discovering and reporting this vulnerability (Oracle CPU Jan 2026). The vulnerability has received broad downstream attention, with numerous Linux distribution vendors (Red Hat, Ubuntu, Debian, SUSE, Amazon Linux) and enterprise software vendors (IBM, Hitachi, Splunk, Dell, Puppet) issuing their own advisories and patches. Coverage has been largely routine, consistent with Oracle's quarterly CPU cycle, with no notable controversy or significant social media discussion beyond standard security advisory tracking.

Additional resources


SourceThis report was generated using AI

Related Amazon Corretto JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34282HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • cpe:2.3:a:oracle:graalvm:*:*:*:*:enterprise:*:*:*
NoYesApr 21, 2026
CVE-2026-22016HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-openjdk-headless
NoYesApr 21, 2026
CVE-2026-22021MEDIUM5.3
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openj9-src
NoYesApr 21, 2026
CVE-2026-22018LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openjdk-devel-slowdebug-debuginfo
NoYesApr 21, 2026
CVE-2026-34268LOW2.9
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.8.0-openjdk-fastdebug-debuginfo
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management