
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-87288 is a high-severity improper access control vulnerability in the Compiler component of Oracle GraalVM, part of Oracle Java SE. The affected version is Oracle GraalVM 25.0.4.1. An unauthenticated remote attacker with network access via HTTP can exploit this vulnerability to achieve full takeover of the affected GraalVM instance. It was published on September 15, 2026, with a patch made available the same day. The CVSS v3.1 base score is 8.1 (High) (GitHub Advisory, Oracle).
The vulnerability is classified as CWE-284 (Improper Access Control), indicating that the Oracle GraalVM Compiler component fails to properly restrict access to a resource from an unauthorized actor (GitHub Advisory). The attack vector is network-based via HTTP, requiring no privileges and no user interaction, though the attack complexity is rated High, meaning exploitation requires specific conditions or non-default configurations to be met. The technical impact is rated as "total" by NVD SSVC analysis, meaning successful exploitation can affect confidentiality, integrity, and availability simultaneously. No detailed technical write-ups or public proof-of-concept code have been identified at this time.
Successful exploitation of CVE-2026-87288 can result in complete takeover of the affected Oracle GraalVM instance, with high impact to confidentiality, integrity, and availability (GitHub Advisory, Oracle). An attacker could execute arbitrary code on the compromised system, access sensitive data processed by GraalVM, and disrupt service availability. Given GraalVM's role as a polyglot runtime environment often used in enterprise Java SE deployments, exploitation could expose application data and potentially enable lateral movement within the hosting environment.
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable due to the High attack complexity rating. The EPSS score is approximately 0.238%, placing this vulnerability in the 15th percentile for exploitation likelihood within 30 days. CVE-2026-87288 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
Oracle has released a patch for CVE-2026-87288, and organizations should upgrade Oracle GraalVM from the affected version 25.0.4.1 to the patched release as soon as it becomes available (Oracle, GitHub Advisory). As an interim measure, restrict network access to Oracle GraalVM instances and limit exposure to untrusted networks, particularly blocking unsolicited HTTP access to GraalVM services. Monitor for any anomalous activity targeting the Compiler component and apply Oracle security updates promptly as part of standard patch management practices.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."