CVE-2026-22016 | Oracle Java SE/GraalVM for JDK/GraalVM Enterprise Edition JAXP improper authorization (Nessus ID 309659 / WID-SEC-2026-1201)
A vulnerability was found in Oracle Java SE, GraalVM for JDK and GraalVM Enterprise Edition and classified as critical. The affected element is an unknown function of the component JAXP. Such manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-22016. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.