CVE-2026-87287
Oracle GraalVM Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-87287 is a high-severity improper access control vulnerability in the Compiler component of Oracle GraalVM, part of Oracle Java SE. It affects Oracle GraalVM version 25.0.4.1 and allows an unauthenticated remote attacker with network access via HTTP to achieve complete compromise of the affected instance. The vulnerability was published on September 15, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Oracle).

Technical details

The vulnerability is classified under CWE-284 (Improper Access Control), indicating that the Oracle GraalVM Compiler component fails to properly restrict access to a resource from unauthorized actors (GitHub Advisory). The attack vector is network-based via HTTP, requiring no privileges and no user interaction, though the attack complexity is rated High, meaning exploitation requires specific conditions or significant effort to be met. Successful exploitation can result in full takeover of the GraalVM instance. No public proof-of-concept code or detailed technical write-ups describing the precise exploitation mechanism have been identified at this time (GitHub Advisory).

Impact

Successful exploitation of CVE-2026-87287 results in complete compromise of the affected Oracle GraalVM instance, with high impact to confidentiality, integrity, and availability. An unauthenticated attacker could execute arbitrary code, read sensitive data, modify system data, and disrupt service availability on the affected host. The scope is limited to the vulnerable component itself (unchanged scope), but a full takeover could enable lateral movement within the broader environment depending on the deployment context (GitHub Advisory, Oracle).

Exploitability

As of the time of publication, there is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-87287 (GitHub Advisory). The EPSS score is approximately 0.238%, placing it in the 15th percentile for exploitation probability within the next 30 days. The NVD SSVC assessment classifies exploitation as "none" and the attack as not automatable, reflecting the high attack complexity requirement. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Mitigation and workarounds

Oracle has released a patch for CVE-2026-87287, and users should update Oracle GraalVM from the affected version 25.0.4.1 to a patched release immediately. As a network-level workaround, administrators should apply network segmentation to restrict HTTP access to GraalVM instances to only trusted networks and IP ranges. Monitoring for anomalous HTTP traffic targeting GraalVM endpoints is also recommended as a compensating control. Patch details are available via GitHub Advisory GHSA-4c7c-57v9-g6f5 (GitHub Advisory, Oracle).

Additional resources


SourceThis report was generated using AI

Related Oracle GraalVM Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-83408HIGH8.1
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • cpe:2.3:a:oracle:graalvm
NoNoSep 15, 2026
CVE-2026-83357HIGH8.1
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • openjdk-8
NoNoSep 15, 2026
CVE-2026-87288HIGH8.1
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • cpe:2.3:a:oracle:graalvm
NoNoSep 15, 2026
CVE-2026-87287HIGH8.1
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • cpe:2.3:a:oracle:graalvm
NoNoSep 15, 2026
CVE-2026-83368HIGH7
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • openjdk-8
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management