CVE-2026-60147
OpenJDK JDK vulnerability analysis and mitigation

Overview

CVE-2026-60147 is a vulnerability in the Security component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, disclosed as part of Oracle's Critical Patch Update in July 2026. Affected versions include Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1; Oracle GraalVM for JDK 17.0.19 and 21.0.11; and Oracle GraalVM Enterprise Edition 21.3.18. The vulnerability was reported to Oracle by the researcher known as "tonghuaroot" and carries a CVSS v3.1 base score of 6.5 (Medium) (Oracle CPU Jul 2026).

Technical details

The vulnerability resides in the Security component of Oracle Java SE and related GraalVM products, allowing an unauthenticated network attacker to exploit it via multiple protocols with low attack complexity and no user interaction required. It can be triggered through APIs in the Security component — for example, via a web service that supplies data to those APIs — and also applies to Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load untrusted code from the internet. The flaw results in unauthorized read access to a subset of accessible data and unauthorized update, insert, or delete access to some accessible data, indicating an integrity and confidentiality impact without availability impact (Oracle CPU Jul 2026).

Impact

Successful exploitation allows an unauthenticated remote attacker to gain unauthorized read access to a subset of Oracle Java SE, GraalVM for JDK, or GraalVM Enterprise Edition accessible data, as well as unauthorized update, insert, or delete access to some of that data. There is no availability impact, but the combined confidentiality and integrity impacts (both rated Low) could expose sensitive information or allow data manipulation in affected Java deployments, including client-side sandboxed environments. The broad version coverage across multiple Java SE releases and GraalVM variants significantly widens the attack surface (Oracle CPU Jul 2026).

Mitigation and workarounds

Oracle has addressed this vulnerability as part of the July 2026 Critical Patch Update. Users should apply the patches provided for their respective product versions: Oracle Java SE (8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1), Oracle GraalVM for JDK (17.0.19, 21.0.11), and Oracle GraalVM Enterprise Edition (21.3.18). As a temporary risk reduction measure, Oracle recommends blocking network protocols required by the attack where feasible, though this may impact application functionality and is not a long-term solution. Oracle strongly recommends applying the CPU patches as soon as possible (Oracle CPU Jul 2026).

Community reactions

The vulnerability was credited to the researcher "tonghuaroot" in Oracle's July 2026 Critical Patch Update advisory. No significant public commentary, vendor statements beyond Oracle's advisory, or notable media coverage specific to CVE-2026-60147 has been identified at this time (Oracle CPU Jul 2026).

Additional resources


SourceThis report was generated using AI

Related OpenJDK JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47063HIGH7.5
  • OpenJDK JDK logoOpenJDK JDK
  • java-21-openjdk-static-libs-slowdebug
NoYesJul 21, 2026
CVE-2026-47057HIGH7.5
  • OpenJDK JDK logoOpenJDK JDK
  • openjdk-11
NoYesJul 21, 2026
CVE-2026-47058HIGH7.4
  • OpenJDK JDK logoOpenJDK JDK
  • java-1.8.0-openjdk-devel-slowdebug
NoYesJul 21, 2026
CVE-2026-60147MEDIUM6.5
  • OpenJDK JDK logoOpenJDK JDK
  • java-21-openjdk-devel
NoYesJul 21, 2026
CVE-2026-47059LOW3.7
  • OpenJDK JDK logoOpenJDK JDK
  • java-1.8.0-openjdk-demo-slowdebug
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management