
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-60147 is a vulnerability in the Security component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, disclosed as part of Oracle's Critical Patch Update in July 2026. Affected versions include Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1; Oracle GraalVM for JDK 17.0.19 and 21.0.11; and Oracle GraalVM Enterprise Edition 21.3.18. The vulnerability was reported to Oracle by the researcher known as "tonghuaroot" and carries a CVSS v3.1 base score of 6.5 (Medium) (Oracle CPU Jul 2026).
The vulnerability resides in the Security component of Oracle Java SE and related GraalVM products, allowing an unauthenticated network attacker to exploit it via multiple protocols with low attack complexity and no user interaction required. It can be triggered through APIs in the Security component — for example, via a web service that supplies data to those APIs — and also applies to Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load untrusted code from the internet. The flaw results in unauthorized read access to a subset of accessible data and unauthorized update, insert, or delete access to some accessible data, indicating an integrity and confidentiality impact without availability impact (Oracle CPU Jul 2026).
Successful exploitation allows an unauthenticated remote attacker to gain unauthorized read access to a subset of Oracle Java SE, GraalVM for JDK, or GraalVM Enterprise Edition accessible data, as well as unauthorized update, insert, or delete access to some of that data. There is no availability impact, but the combined confidentiality and integrity impacts (both rated Low) could expose sensitive information or allow data manipulation in affected Java deployments, including client-side sandboxed environments. The broad version coverage across multiple Java SE releases and GraalVM variants significantly widens the attack surface (Oracle CPU Jul 2026).
Oracle has addressed this vulnerability as part of the July 2026 Critical Patch Update. Users should apply the patches provided for their respective product versions: Oracle Java SE (8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1), Oracle GraalVM for JDK (17.0.19, 21.0.11), and Oracle GraalVM Enterprise Edition (21.3.18). As a temporary risk reduction measure, Oracle recommends blocking network protocols required by the attack where feasible, though this may impact application functionality and is not a long-term solution. Oracle strongly recommends applying the CPU patches as soon as possible (Oracle CPU Jul 2026).
The vulnerability was credited to the researcher "tonghuaroot" in Oracle's July 2026 Critical Patch Update advisory. No significant public commentary, vendor statements beyond Oracle's advisory, or notable media coverage specific to CVE-2026-60147 has been identified at this time (Oracle CPU Jul 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."