Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22007

16
FAUCET Score

OVERVIEW CVE-2026-22007 is a security vulnerability affecting multiple Oracle Java SE products and GraalVM editions, including Java SE versions 8u481 through 26, GraalVM for JDK 17.0.18 and 21.0.10, and GraalVM Enterprise Edition 21.3.17. The vulnerability resides in the Security component and allows unauthorized read access to a subset of accessible data when exploited through APIs or web services that supply data to affected components. SEVERITY The vulnerability carries a CVSS 3.1 base score of 2.9, classified as LOW severity, with impacts limited to confidentiality. Attack requirements are relatively stringent, requiring local access to the infrastructure (AV:L) with high complexity (AC:H) and no privilege or user interaction needed. The attack vector is local only, meaning remote exploitation is not possible, and successful compromise results solely in unauthorized read access without integrity or availability impacts. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and community attention is minimal, as indicated by an EPSS score of 0.00012 and a FAUCET risk score of 26/100. No publicly available exploit code has been reported, and the "Inactive" designation on the Hot List indicates this is not a priority concern within the cybersecurity community at this time.

Impacted Technologies

VendorProductVersion(s)CPE
21.3.17CPE matchmatch criteria
cpe:2.3:a:oracle:graalvm:21.3.17:*:*:*:enterprise:*:*:*
17.0.18CPE matchmatch criteria
cpe:2.3:a:oracle:graalvm_for_jdk:17.0.18:*:*:*:*:*:*:*
21.0.10CPE matchmatch criteria
cpe:2.3:a:oracle:graalvm_for_jdk:21.0.10:*:*:*:*:*:*:*
1.8.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.8.0:update481:*:*:-:*:*:*
1.8.0CPE matchmatch criteria
cpe:2.3:a:oracle:jre:1.8.0:update481:*:*:enterprise_performance_pack:*:*:*

CVSS Data

CVSS version used by this source: 3.1

2.9LOW

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.4
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.12%
Probability of exploitation in next 30 days
EPSS Percentile
2.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0012 is in the 3rd percentile among its peer group of 747 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (25)

ubuntupatch availablevia ubuntu_usn
Product: openjdk-26 (questing)Fixed in: 26.0.1+8-2~25.10.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-26 (resolute)Fixed in: 26.0.1+8-2~26.04.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-25 (jammy)Fixed in: 25.0.3+9-2~22.04.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-25 (noble)Fixed in: 25.0.3+9-2~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-25 (questing)Fixed in: 25.0.3+9-2~25.10.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-25 (resolute)Fixed in: 25.0.3+9-2~26.04.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-25-crac (questing)Fixed in: 25.0.3+9-0ubuntu1~25.10.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-25-crac (resolute)Fixed in: 25.0.3+9-0ubuntu1~26.04.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-21-crac (questing)Fixed in: 21.0.11+10-0ubuntu1~25.10.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-21-crac (resolute)Fixed in: 21.0.11+10-0ubuntu1~26.04.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-17-crac (questing)Fixed in: 17.0.19+10-0ubuntu1~25.10.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-17-crac (resolute)Fixed in: 17.0.19+10-0ubuntu1~26.04.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-lts (bionic)Fixed in: 11.0.31+11-1ubuntu1~18.04.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-lts (focal)Fixed in: 11.0.31+11-1ubuntu1~20.04.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-lts (jammy)Fixed in: 11.0.31+11-1ubuntu1~22.04.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-lts (noble)Fixed in: 11.0.31+11-1ubuntu1~24.04.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-lts (questing)Fixed in: 11.0.31+11-1ubuntu1~25.10.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-lts (resolute)Fixed in: 11.0.31+11-1ubuntu1~26.04.2
ubuntupatch availablevia ubuntu_usn
Product: openjdk-8 (bionic)Fixed in: 8u492-ga~us2-0ubuntu1~18.04.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-8 (focal)Fixed in: 8u492-ga~us2-0ubuntu1~20.04.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-8 (jammy)Fixed in: 8u492-ga~us2-0ubuntu1~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-8 (noble)Fixed in: 8u492-ga~us2-0ubuntu1~24.04.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-8 (questing)Fixed in: 8u492-ga~us2-0ubuntu1~25.10.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-8 (resolute)Fixed in: 8u492-ga~us2-0ubuntu1~26.04.1
ubuntupatch availablevia ubuntu_usn
Product: openjdk-8 (xenial)Fixed in: 8u492-ga~us2-0ubuntu1~16.04.1

Vendor Advisories (7)

ubuntuUSN-8341-1

OpenJDK 26 vulnerabilities

May 28, 2026
ubuntuUSN-8339-1

OpenJDK 25 vulnerabilities

May 28, 2026
ubuntuUSN-8334-1

CRaC JDK 25 vulnerabilities

May 28, 2026
ubuntuUSN-8333-1

CRaC JDK 21 vulnerabilities

May 28, 2026
ubuntuUSN-8332-1

CRaC JDK 17 vulnerabilities

May 28, 2026
ubuntuUSN-8331-1

OpenJDK 11 vulnerabilities

May 28, 2026
ubuntuUSN-8330-1

OpenJDK 8 vulnerabilities

May 28, 2026

References

oracle.com / security-alerts/cpuapr2026.html
Vendor Advisory