
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21932 is an integrity bypass vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting the AWT and JavaFX (Desktop) components, specifically related to improper handling of URIs. Disclosed as part of Oracle's January 2026 Critical Patch Update (CPU), it affects Oracle Java SE versions 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, and 25.0.1; Oracle GraalVM for JDK 17.0.17 and 21.0.9; and Oracle GraalVM Enterprise Edition 21.3.16. The vulnerability was reported to Oracle by Mingijung of WebSec Lab (Oracle CPU Jan 2026). It carries a CVSS v3.1 base score of 7.4 (High) (Red Hat Bugzilla, Oracle CPU Jan 2026).
The root cause is classified as CWE-1287 (Improper Validation of Specified Type of Input), specifically involving improper handling of URIs in the Desktop.browse() method. According to the Red Hat Bugzilla entry, Desktop.browse() will execute a program if the URI is a filename, whereas the documentation specifies that the default browser should be used to open the URI — representing a type confusion/validation bypass (Red Hat Bugzilla). The attack vector is network-based, requires no privileges, but does require user interaction (e.g., a user must open a malicious Java Web Start application or sandboxed applet that loads untrusted code). The vulnerability has a changed scope, meaning successful exploitation can impact resources beyond the vulnerable component itself. Upstream fix commits are available for OpenJDK 8, 11, 17, 21, and 25 (Red Hat Bugzilla).
Successful exploitation allows an unauthenticated remote attacker to bypass Java security controls and perform unauthorized creation, deletion, or modification of critical or all accessible data within the Java environment, with no confidentiality or availability impact. The changed scope indicates that attacks may significantly impact additional products or resources beyond the directly vulnerable Java component. This vulnerability specifically affects Java Web Start applications and sandboxed Java applets that load untrusted code; server-side Java deployments running only trusted code are not affected (Oracle CPU Jan 2026, Red Hat Bugzilla).
Oracle has released patches for all affected versions as part of the January 2026 Critical Patch Update. Fixed versions include Oracle Java SE 8u481, 11.0.30, 17.0.18, 21.0.10, and 25.0.2 (Red Hat Bugzilla). Downstream vendors including Red Hat (RHSA-2026:0849, RHSA-2026:0900, RHSA-2026:1606), Ubuntu (USN-7995-1, USN-7998-1, USN-8000-1), Debian, SUSE, and Amazon Linux have also released updated packages. IBM has issued advisories for affected products including IBM i, IBM MQ, IBM Business Automation Workflow, IBM Guardium, and others (IBM i Advisory). Organizations should prioritize upgrading to patched Java SE and GraalVM versions; as a temporary measure, restricting execution of untrusted Java Web Start applications and applets can reduce exposure (Oracle CPU Jan 2026).
Oracle credited Mingijung of WebSec Lab for discovering and reporting this vulnerability (Oracle CPU Jan 2026). The vulnerability has received broad downstream attention, with numerous Linux distribution vendors (Red Hat, Ubuntu, Debian, SUSE, Amazon Linux) and enterprise software vendors (IBM, Hitachi, Splunk, Dell, Puppet) issuing their own advisories and patches. Coverage has been largely routine, consistent with Oracle's quarterly CPU cycle, with no notable controversy or significant social media discussion beyond standard security advisory tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."