CVE-2026-34268
Amazon Corretto JDK vulnerability analysis and mitigation

Overview

CVE-2026-34268 is an information disclosure vulnerability in the Security component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, disclosed as part of Oracle's April 2026 Critical Patch Update. Affected versions include Oracle Java SE 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, and 26; Oracle GraalVM for JDK 17.0.18 and 21.0.10; and Oracle GraalVM Enterprise Edition 21.3.17. The vulnerability was reported by Ken Pyle and published on April 21, 2026. It carries a CVSS v3.1 base score of 2.9 (Low) (Oracle CPU Apr 2026, Github Advisory).

Technical details

The root cause of CVE-2026-34268 is the use of a broken or risky cryptographic algorithm (CWE-327) in Java's key generation process, leading to exposure of sensitive information (CWE-200). Specifically, under certain circumstances, multiple distinct passwords can generate the same cryptographic keys when using DES PBKDF (Password-Based Key Derivation Function), a known-weak algorithm (Red Hat Bugzilla). The attack vector is local (AV:L) with high complexity (AC:H), requiring no privileges and no user interaction. Exploitation can occur via APIs in the Security component — including through web services that supply data to those APIs — and also applies to sandboxed Java Web Start applications or applets loading untrusted code from the internet (Oracle CPU Apr 2026).

Impact

Successful exploitation results in unauthorized read access to a subset of data accessible by the affected Java SE or GraalVM instance, with impact limited to confidentiality (no integrity or availability impact). The vulnerability does not allow remote unauthenticated access over a network in the traditional sense; an attacker must have local logon access to the infrastructure where the affected Java runtime executes. The practical risk is that cryptographic key collisions could allow an attacker with local access to derive or predict keys generated by other users or processes, potentially exposing protected data (Oracle CPU Apr 2026, Github Advisory).

Mitigation and workarounds

Oracle has released fixed versions addressing this vulnerability: Java SE 8u491, 11.0.31, 17.0.19, 21.0.11, and 25.0.3 (Red Hat Bugzilla). Downstream vendors including Red Hat (RHSA-2026:22139, RHSA-2026:22328), IBM (Semeru Runtime, SDK, App Connect Enterprise, Sterling Transformation Extender, and others), SUSE, Debian, Ubuntu, and Amazon Linux have also released updated packages (Oracle CPU Apr 2026). Organizations should prioritize upgrading affected Java SE and GraalVM deployments to the patched versions, and restrict local infrastructure access where feasible to reduce attack surface. No configuration-based workaround is available; patching is the recommended remediation.

Community reactions

Oracle acknowledged the vulnerability in its April 2026 Critical Patch Update, crediting Ken Pyle for the report (Oracle CPU Apr 2026). Red Hat, IBM, SUSE, Debian, Ubuntu, and other major Linux and enterprise vendors have issued downstream advisories and patches, reflecting broad ecosystem attention to the Java SE quarterly CPU cycle. No notable independent researcher commentary or significant social media discussion specific to this low-severity vulnerability has been identified.

Additional resources


SourceThis report was generated using AI

Related Amazon Corretto JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34282HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-amazon-corretto-devel
NoYesApr 21, 2026
CVE-2026-22016HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-ibm-devel
NoYesApr 21, 2026
CVE-2026-22021MEDIUM5.3
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.7.0-openjdk-demo
NoYesApr 21, 2026
CVE-2026-22018LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-openjdk-headless
NoYesApr 21, 2026
CVE-2026-34268LOW2.9
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1_8_0-openjdk-demo
NoYesApr 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management