CVE-2026-22016
7.5Oracle · Java SE, GraalVM for JDK, GraalVM Enterprise Edition
A vulnerability in the JAXP component of Oracle Java SE and GraalVM allows unauthenticated remote attackers to access sensitive data.
Executive summary
An unauthenticated remote vulnerability in Oracle Java SE and GraalVM components poses a high risk of unauthorized data access.
Vulnerability
This is an easily exploitable flaw in the JAXP component that permits an unauthenticated attacker with network access to compromise the integrity of data via multiple protocols, including web services or sandboxed applications.
Business impact
The vulnerability carries a CVSS 3.1 base score of 7.5, classifying it as a High severity issue due to the ease of remote exploitation without authentication. Successful exploitation allows an attacker to gain unauthorized access to critical data, potentially leading to widespread information disclosure and significant compliance or privacy breaches.
Remediation
Immediate Action: Review the official Oracle Security Alert for April 2026 to identify and apply the relevant Critical Patch Update (CPU) for your specific Java environment.
Proactive Monitoring: Monitor network traffic for unusual JAXP-related API calls and audit application access logs for attempts to interact with Java-based services from unauthorized external sources.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to filter malicious XML or SOAP payloads that may target JAXP vulnerabilities in your web-facing applications.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the High severity rating and the broad applicability of this vulnerability to various Java deployments, organizations must prioritize patching. Identify all instances of affected Java SE and GraalVM versions within your infrastructure and apply the vendor-provided updates immediately to prevent unauthorized data access.
More Oracle CVEs
Sources
- Oracle Advisory Vendor advisory