
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22016 is a vulnerability in the JAXP (Java API for XML Processing) component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, disclosed as part of Oracle's April 2026 Critical Patch Update. The flaw allows unauthenticated remote attackers to gain unauthorized access to critical data accessible by the affected Java runtime. Affected versions include Oracle Java SE 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, and 26; Oracle GraalVM for JDK 17.0.18 and 21.0.10; and Oracle GraalVM Enterprise Edition 21.3.17. It was published on April 21, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Oracle CPU Apr 2026, Github Advisory).
The root cause of CVE-2026-22016 is that XPath.compile creates a new XPathExpression where the XML security manager (xmlSecMgr) is null, leaving the JAXP component open to XML External Entity (XXE) and XML Entity Expansion (XEE) attacks (CWE-611, CWE-200) (Red Hat Bugzilla). The vulnerability is exploitable over the network via multiple protocols without authentication or user interaction, and can be triggered through web services that supply data to JAXP APIs, or through sandboxed Java Web Start applications and Java applets that load untrusted code from the internet (Oracle CPU Apr 2026). The vulnerability was reported to Oracle by Thomas Beckers of Soptim (Oracle CPU Apr 2026). Upstream OpenJDK commits addressing the flaw are publicly available for versions 8, 11, 17, 21, and 25 (Red Hat Bugzilla).
Successful exploitation results in high confidentiality impact — an unauthenticated attacker can gain complete unauthorized access to all data accessible by the affected Oracle Java SE, GraalVM for JDK, or GraalVM Enterprise Edition instance. There is no integrity or availability impact. The vulnerability is particularly concerning in server-side deployments where Java web services process XML from untrusted sources, as well as in client-side environments running sandboxed Java Web Start applications or applets. Downstream IBM products including IBM Semeru Runtime, IBM SDK Java Technology Edition, IBM App Connect Enterprise, IBM InfoSphere Information Server, IBM Sterling Transformation Extender, and others are also affected (Oracle CPU Apr 2026, Github Advisory).
Oracle has released fixed versions as part of the April 2026 Critical Patch Update: Oracle Java SE 8u491, 11.0.31, 17.0.19, 21.0.11, and 25.0.3 address this vulnerability (Red Hat Bugzilla). Downstream vendors including Red Hat (RHSA-2026:9254, RHSA-2026:9255, RHSA-2026:22139, RHSA-2026:22328), IBM, SUSE, Debian, Ubuntu, and Amazon Linux have also released updated packages. Organizations should prioritize upgrading all affected Java SE and GraalVM installations to patched versions. As a temporary measure, restricting network access to services that process XML via JAXP APIs and disabling untrusted XML input sources can reduce exposure (Oracle CPU Apr 2026).
The vulnerability received standard coverage from security aggregators and Linux distribution security teams, with patch advisories issued by Red Hat, SUSE, Debian, Ubuntu, Amazon Linux, and IBM shortly after Oracle's April 2026 CPU release. Azul Systems published a blog post highlighting the importance of applying Java runtime security updates promptly (Oracle CPU Apr 2026). No notable independent researcher commentary or significant social media discussion beyond routine CVE alert posts has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."