CVE-2026-22016: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. in Oracle Corporation Oracle Java SE
CVE-2026-22016 is a high-severity vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting multiple supported versions. It involves the JAXP component and allows an unauthenticated attacker with network access via multiple protocols to gain unauthorized access to critical or all accessible data. The vulnerability can be exploited through APIs, including web services that supply data to these APIs, and affects Java deployments running sandboxed Java Web Start applications or applets that load untrusted code relying on the Java sandbox. The CVSS 3. 1 base score is 7. 5, reflecting high confidentiality impact without integrity or availability impact. Oracle has published a Critical Patch Update advisory covering this and many other vulnerabilities, strongly recommending patch application. However, the specific patch status for this vulnerability is not explicitly confirmed in the advisory content provided.
AI Analysis
Technical Summary
This vulnerability affects the JAXP component in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition across multiple versions including 8u481, 11.0.30, 17.0.18, 21.0.10, 25.0.2, and 26. It allows an unauthenticated attacker with network access via multiple protocols to exploit APIs and gain unauthorized access to critical or all accessible data. The vulnerability also impacts Java deployments that run sandboxed Java Web Start applications or applets loading untrusted code relying on the Java sandbox for security. The CVSS 3.1 vector indicates network attack vector, low attack complexity, no privileges or user interaction required, unchanged scope, and high confidentiality impact. Oracle’s April 2026 Critical Patch Update advisory includes this vulnerability among 481 security patches, but does not explicitly confirm patch availability or remediation level for this specific CVE.
Potential Impact
Successful exploitation can lead to unauthorized access to critical or all accessible data within Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition environments. The confidentiality of sensitive information is compromised, but there is no impact on integrity or availability according to the CVSS vector. The vulnerability can be exploited remotely without authentication or user interaction, increasing the risk of data exposure in affected systems.
Mitigation Recommendations
Oracle’s April 2026 Critical Patch Update advisory includes this vulnerability among numerous security patches and strongly recommends applying these patches without delay. Although the advisory does not explicitly confirm the patch status for CVE-2026-22016, customers should promptly apply the April 2026 Critical Patch Update to mitigate this vulnerability. Staying on actively supported versions and timely patching are critical. If patch application is not immediately possible, consider restricting network access to affected services and APIs as a temporary measure until patches can be applied.
CVE-2026-22016: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. in Oracle Corporation Oracle Java SE
Description
CVE-2026-22016 is a high-severity vulnerability in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition affecting multiple supported versions. It involves the JAXP component and allows an unauthenticated attacker with network access via multiple protocols to gain unauthorized access to critical or all accessible data. The vulnerability can be exploited through APIs, including web services that supply data to these APIs, and affects Java deployments running sandboxed Java Web Start applications or applets that load untrusted code relying on the Java sandbox. The CVSS 3. 1 base score is 7. 5, reflecting high confidentiality impact without integrity or availability impact. Oracle has published a Critical Patch Update advisory covering this and many other vulnerabilities, strongly recommending patch application. However, the specific patch status for this vulnerability is not explicitly confirmed in the advisory content provided.
CVSS v3.1
Score 7.5high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects the JAXP component in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition across multiple versions including 8u481, 11.0.30, 17.0.18, 21.0.10, 25.0.2, and 26. It allows an unauthenticated attacker with network access via multiple protocols to exploit APIs and gain unauthorized access to critical or all accessible data. The vulnerability also impacts Java deployments that run sandboxed Java Web Start applications or applets loading untrusted code relying on the Java sandbox for security. The CVSS 3.1 vector indicates network attack vector, low attack complexity, no privileges or user interaction required, unchanged scope, and high confidentiality impact. Oracle’s April 2026 Critical Patch Update advisory includes this vulnerability among 481 security patches, but does not explicitly confirm patch availability or remediation level for this specific CVE.
Potential Impact
Successful exploitation can lead to unauthorized access to critical or all accessible data within Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition environments. The confidentiality of sensitive information is compromised, but there is no impact on integrity or availability according to the CVSS vector. The vulnerability can be exploited remotely without authentication or user interaction, increasing the risk of data exposure in affected systems.
Mitigation Recommendations
Oracle’s April 2026 Critical Patch Update advisory includes this vulnerability among numerous security patches and strongly recommends applying these patches without delay. Although the advisory does not explicitly confirm the patch status for CVE-2026-22016, customers should promptly apply the April 2026 Critical Patch Update to mitigate this vulnerability. Staying on actively supported versions and timely patching are critical. If patch application is not immediately possible, consider restricting network access to affected services and APIs as a temporary measure until patches can be applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- oracle
- Date Reserved
- 2026-01-05T18:07:34.728Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.oracle.com/security-alerts/cpuapr2026.html","vendor":"Oracle"}]
Threat ID: 69e7e59e19fe3cd2cdf9f6f2
Added to database: 4/21/2026, 9:01:18 PM
Last enriched: 4/29/2026, 11:32:45 AM
Last updated: 6/6/2026, 8:17:10 AM
Views: 234
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.