
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-83357 is a path traversal vulnerability in the Compiler component of Oracle GraalVM for JDK and Oracle GraalVM, classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). It affects Oracle GraalVM for JDK 17 (version 23.0.13.1), Oracle GraalVM for JDK 21 (version 23.1.12.1), and Oracle GraalVM (version 25.0.4.1). The vulnerability was disclosed and patched on September 15, 2026, as part of Oracle's Critical Security Patch Update (CSPU). It carries a CVSS v3.1 base score of 8.1 (High) (Oracle Advisory, GitHub Advisory).
The vulnerability is rooted in improper path validation within the GraalVM Compiler component (CWE-22), where external input is used to construct pathnames without adequately neutralizing special elements (e.g., ../ sequences), allowing traversal outside restricted directories. An unauthenticated attacker with network access via HTTP can exploit this flaw without requiring any user interaction or privileges, though the attack complexity is rated High, indicating that specific conditions or timing must be met. Associated attack patterns include path traversal (CAPEC-126), URL encoding bypass (CAPEC-64), and use of escaped or alternate-encoded slashes (CAPEC-78, CAPEC-79) to circumvent validation logic (Oracle Advisory, GitHub Advisory). No public proof-of-concept or detailed technical write-up has been published as of the disclosure date.
Successful exploitation can result in complete takeover of the affected Oracle GraalVM for JDK or Oracle GraalVM instance, with high impact to confidentiality, integrity, and availability. An attacker could execute arbitrary code, read or modify sensitive files and system configurations, and disrupt service availability. The scope is unchanged, meaning the impact is contained to the vulnerable component itself, but a full system compromise of the GraalVM runtime environment could enable further lateral movement within the hosting infrastructure (Oracle Advisory, GitHub Advisory).
As of the disclosure date, there is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the attack is not automatable due to High attack complexity. The EPSS score is approximately 0.305% (23rd percentile), indicating a low near-term probability of exploitation. CVE-2026-83357 has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
Oracle has released patches for all affected versions as part of the September 2026 Critical Security Patch Update (CSPU). Organizations should apply the available patches for Oracle GraalVM for JDK 17 (23.0.13.1), Oracle GraalVM for JDK 21 (23.1.12.1), and Oracle GraalVM (25.0.4.1) immediately. As interim measures, Oracle recommends restricting network access to GraalVM instances to trusted sources only, blocking HTTP access from untrusted networks where feasible, and monitoring for suspicious HTTP requests targeting GraalVM services. Oracle strongly cautions that network-blocking workarounds are not long-term solutions and do not address the underlying vulnerability (Oracle Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."