CVE-2026-16441CWE-758

CVE-2026-16441

Critical · published July 21, 2026

CVSS v3.1
9.6
EPSS
0%
Percentile
20.2
In the wild
Unconfirmed
What it is

In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method.

The record
Technical detail
CVSS v3.1
9.6 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00280 · 20.2th percentile
Weakness
CWE-758 · Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
Published
2026-07-21T23:17Z
Affected products (1)
ProductVersionsFixed in
eclipse/openj9≥ 0.8.0, < 0.60.00.60.0
References (3)
EPSS history
Timeline
  • 21 JUL 18:07Z
    Eclipse OpenJ9 : Method resolution default method precedence failure
    cvelistv5