« Back to list

CVE-2026-47057

Status: AnalyzedHigh (7.5)—

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs.

Read full descriptionShow less

This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-47057",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-47057",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-07-23T16:06:31.941991Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert_us@oracle.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert_us@oracle.com",
      "affectedData": [
        {
          "vendor": "Oracle Corporation",
          "product": "Oracle Java SE",
          "versions": [
            {
              "status": "affected",
              "version": "8u491"
            },
            {
              "status": "affected",
              "version": "8u491-perf"
            },
            {
              "status": "affected",
              "version": "11.0.31"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-07-21T22:17:11.483",
  "references": [
    {
      "url": "https://www.oracle.com/security-alerts/cpujul2026.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert_us@oracle.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Vulnerability in Oracle Java SE (component: Scripting).  Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and  11.0.31. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)."
    }
  ],
  "lastModified": "2026-08-03T18:52:45.383",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:jre:1.8.0:update491:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0DE5FE4-2686-4C60-B4C6-2AC9E7A538D5"
            },
            {
              "criteria": "cpe:2.3:a:oracle:jre:1.8.0:update491:*:*:enterprise_performance_pack:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D60FEE5A-22B8-4F6C-AF4F-C8B317C2D102"
            },
            {
              "criteria": "cpe:2.3:a:oracle:jre:11.0.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB3E4F54-F4A3-40E8-8662-EA181BEE59E5"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:jdk:1.8.0:update491:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26A3520C-C410-4AC7-93CF-69F5CBD23CA8"
            },
            {
              "criteria": "cpe:2.3:a:oracle:jdk:1.8.0:update491:*:*:enterprise_performance_pack:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "35F51EB5-DF63-47B3-9EFF-E52B0538747E"
            },
            {
              "criteria": "cpe:2.3:a:oracle:jdk:11.0.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CBF2718-F1CA-4BB6-8FE5-C106C444DFA6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert_us@oracle.com"
}