CVE-2026-87288
Oracle GraalVM Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-87288 is a high-severity improper access control vulnerability in the Compiler component of Oracle GraalVM, part of Oracle Java SE. The affected version is Oracle GraalVM 25.0.4.1. An unauthenticated remote attacker with network access via HTTP can exploit this vulnerability to achieve full takeover of the affected GraalVM instance. It was published on September 15, 2026, with a patch made available the same day. The CVSS v3.1 base score is 8.1 (High) (GitHub Advisory, Oracle).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), indicating that the Oracle GraalVM Compiler component fails to properly restrict access to a resource from an unauthorized actor (GitHub Advisory). The attack vector is network-based via HTTP, requiring no privileges and no user interaction, though the attack complexity is rated High, meaning exploitation requires specific conditions or non-default configurations to be met. The technical impact is rated as "total" by NVD SSVC analysis, meaning successful exploitation can affect confidentiality, integrity, and availability simultaneously. No detailed technical write-ups or public proof-of-concept code have been identified at this time.

Impact

Successful exploitation of CVE-2026-87288 can result in complete takeover of the affected Oracle GraalVM instance, with high impact to confidentiality, integrity, and availability (GitHub Advisory, Oracle). An attacker could execute arbitrary code on the compromised system, access sensitive data processed by GraalVM, and disrupt service availability. Given GraalVM's role as a polyglot runtime environment often used in enterprise Java SE deployments, exploitation could expose application data and potentially enable lateral movement within the hosting environment.

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable due to the High attack complexity rating. The EPSS score is approximately 0.238%, placing this vulnerability in the 15th percentile for exploitation likelihood within 30 days. CVE-2026-87288 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.

Mitigation and workarounds

Oracle has released a patch for CVE-2026-87288, and organizations should upgrade Oracle GraalVM from the affected version 25.0.4.1 to the patched release as soon as it becomes available (Oracle, GitHub Advisory). As an interim measure, restrict network access to Oracle GraalVM instances and limit exposure to untrusted networks, particularly blocking unsolicited HTTP access to GraalVM services. Monitor for any anomalous activity targeting the Compiler component and apply Oracle security updates promptly as part of standard patch management practices.

Additional resources


SourceThis report was generated using AI

Related Oracle GraalVM Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-83408HIGH8.1
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • cpe:2.3:a:oracle:graalvm
NoNoSep 15, 2026
CVE-2026-83357HIGH8.1
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • openjdk-8
NoNoSep 15, 2026
CVE-2026-87288HIGH8.1
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • cpe:2.3:a:oracle:graalvm
NoNoSep 15, 2026
CVE-2026-87287HIGH8.1
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • cpe:2.3:a:oracle:graalvm
NoNoSep 15, 2026
CVE-2026-83368HIGH7
  • Oracle GraalVM Enterprise logoOracle GraalVM Enterprise
  • openjdk-8
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management