OVERVIEW CVE-2026-22007 is a security vulnerability affecting multiple Oracle Java SE products and GraalVM editions, including Java SE versions 8u481 through 26, GraalVM for JDK 17.0.18 and 21.0.10, and GraalVM Enterprise Edition 21.3.17. The vulnerability resides in the Security component and allows unauthorized read access to a subset of accessible data when exploited through APIs or web services that supply data to affected components. SEVERITY The vulnerability carries a CVSS 3.1 base score of 2.9, classified as LOW severity, with impacts limited to confidentiality. Attack requirements are relatively stringent, requiring local access to the infrastructure (AV:L) with high complexity (AC:H) and no privilege or user interaction needed. The attack vector is local only, meaning remote exploitation is not possible, and successful compromise results solely in unauthorized read access without integrity or availability impacts. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and community attention is minimal, as indicated by an EPSS score of 0.00012 and a FAUCET risk score of 26/100. No publicly available exploit code has been reported, and the "Inactive" designation on the Hot List indicates this is not a priority concern within the cybersecurity community at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
21.3.17CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:21.3.17:*:*:*:enterprise:*:*:* | ||
17.0.18CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm_for_jdk:17.0.18:*:*:*:*:*:*:* | ||
21.0.10CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm_for_jdk:21.0.10:*:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update481:*:*:-:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:oracle:jre:1.8.0:update481:*:*:enterprise_performance_pack:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenJDK 26 vulnerabilities
May 28, 2026OpenJDK 25 vulnerabilities
May 28, 2026CRaC JDK 25 vulnerabilities
May 28, 2026CRaC JDK 21 vulnerabilities
May 28, 2026CRaC JDK 17 vulnerabilities
May 28, 2026OpenJDK 11 vulnerabilities
May 28, 2026OpenJDK 8 vulnerabilities
May 28, 2026