Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). (CVE-2026-87287)
A high-severity vulnerability (CVE-2026-87287) exists in the Oracle GraalVM component of Oracle Java SE, specifically in the Compiler. The affected version is Oracle GraalVM 25.0.4.1. This vulnerability is difficult to exploit but allows an unauthenticated attacker with network access via HTTP to potentially take over the Oracle GraalVM instance. The CVSS 3.1 base score is 8.1, indicating significant confidentiality, integrity, and availability impacts. No explicit patch or remediation details are provided in the vendor advisory.
AI Analysis
Technical Summary
CVE-2026-87287 is a vulnerability in the Oracle GraalVM product within Oracle Java SE's Compiler component. It affects Oracle GraalVM version 25.0.4.1. The flaw allows an unauthenticated attacker with network access over HTTP to compromise the GraalVM environment, potentially leading to full takeover. The vulnerability has a CVSS 3.1 score of 8.1, reflecting high impact on confidentiality, integrity, and availability. The vendor advisory references Oracle's general security alerts page but does not provide specific patch or mitigation information for this CVE.
Potential Impact
Successful exploitation can result in complete compromise of Oracle GraalVM, impacting confidentiality, integrity, and availability of the affected system. The vulnerability requires network access via HTTP but no authentication, though it is described as difficult to exploit.
Mitigation Recommendations
Patch status is not yet confirmed — check the Oracle advisory at https://www.oracle.com/security-alerts/oracle-open-source-cves-outside-other-oracle-public-documents.html for current remediation guidance. No specific mitigation or patch information is provided in the available vendor advisory content.
Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). (CVE-2026-87287)
Description
A high-severity vulnerability (CVE-2026-87287) exists in the Oracle GraalVM component of Oracle Java SE, specifically in the Compiler. The affected version is Oracle GraalVM 25.0.4.1. This vulnerability is difficult to exploit but allows an unauthenticated attacker with network access via HTTP to potentially take over the Oracle GraalVM instance. The CVSS 3.1 base score is 8.1, indicating significant confidentiality, integrity, and availability impacts. No explicit patch or remediation details are provided in the vendor advisory.
CVSS v3.1
Score 8.1high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-87287 is a vulnerability in the Oracle GraalVM product within Oracle Java SE's Compiler component. It affects Oracle GraalVM version 25.0.4.1. The flaw allows an unauthenticated attacker with network access over HTTP to compromise the GraalVM environment, potentially leading to full takeover. The vulnerability has a CVSS 3.1 score of 8.1, reflecting high impact on confidentiality, integrity, and availability. The vendor advisory references Oracle's general security alerts page but does not provide specific patch or mitigation information for this CVE.
Potential Impact
Successful exploitation can result in complete compromise of Oracle GraalVM, impacting confidentiality, integrity, and availability of the affected system. The vulnerability requires network access via HTTP but no authentication, though it is described as difficult to exploit.
Mitigation Recommendations
Patch status is not yet confirmed — check the Oracle advisory at https://www.oracle.com/security-alerts/oracle-open-source-cves-outside-other-oracle-public-documents.html for current remediation guidance. No specific mitigation or patch information is provided in the available vendor advisory content.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4c7c-57v9-g6f5
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-87287"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aaa07d855bf5e2cf5ea2d24
Added to database: 09/16/2026, 03:07:04 UTC
Last enriched: 09/16/2026, 03:19:03 UTC
Last updated: 09/16/2026, 23:01:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.