CVE-2026-34268
Received Received - Intake
Unauthorized Data Access Vulnerability in Oracle Java SE Security APIs

Publication date: 2026-04-21

Last updated on: 2026-04-27

Assigner: Oracle

Description
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.2, 26; Oracle GraalVM for JDK: 17.0.18 and 21.0.10; Oracle GraalVM Enterprise Edition: 21.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition executes to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 2.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-21
Last Modified
2026-04-27
Generated
2026-05-07
AI Q&A
2026-04-22
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 19 associated CPEs
Vendor Product Version / Range
oracle jre 1.8.0
oracle jre 1.8.0
oracle jre 1.8.0
oracle jre 11.0.30
oracle jre 17.0.18
oracle jre 21.0.10
oracle jre 25.0.2
oracle jre 26
oracle jdk 1.8.0
oracle jdk 1.8.0
oracle jdk 1.8.0
oracle jdk 11.0.30
oracle jdk 17.0.18
oracle jdk 21.0.10
oracle jdk 25.0.2
oracle jdk 26
oracle graalvm 21.3.17
oracle graalvm_for_jdk 17.0.18
oracle graalvm_for_jdk 21.0.10
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, specifically in the Security component. It affects several supported versions of these products.

The vulnerability is difficult to exploit and requires an unauthenticated attacker to have logon access to the infrastructure where these Oracle products execute. The attacker can then compromise the affected Oracle Java SE or GraalVM products.

Successful exploitation can result in unauthorized read access to some accessible data within these products. The vulnerability can be exploited via APIs in the affected component, for example through a web service supplying data to these APIs.

It also applies to Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and run untrusted code relying on the Java sandbox for security.


How can this vulnerability impact me? :

If exploited, this vulnerability can allow an attacker with access to the infrastructure to gain unauthorized read access to certain data within Oracle Java SE or GraalVM environments.

Because the vulnerability is difficult to exploit and requires local logon access, the risk is somewhat limited to environments where an attacker can already access the system.

However, unauthorized data disclosure could lead to information leakage, which might affect confidentiality of sensitive information processed or stored by these Java environments.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

This vulnerability allows unauthorized read access to a subset of data accessible by Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. Such unauthorized access to data could potentially impact compliance with data protection regulations like GDPR and HIPAA, which require strict controls on unauthorized data access and confidentiality.

However, the vulnerability is described as difficult to exploit and requires an attacker to have logon access to the infrastructure where the affected products execute, which may limit the risk in some environments.

No specific information is provided about direct impacts on compliance frameworks or regulatory requirements in the available context.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart