PT-2026-62218 · Oracle · Java Se+1

CVE-2026-47058

·

Published

2026-07-21

·

Updated

2026-08-25

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Oracle Java SE version 8u491 Oracle Java SE version 8u491-perf Oracle Java SE versions prior to 11.0.32
Description A flaw in the Scripting component allows an unauthenticated attacker with network access via multiple protocols to compromise the system. This can be achieved by using APIs in the affected component, such as through a web service that provides data to those APIs. The issue also impacts Java deployments that load and run untrusted code, such as sandboxed Java Web Start applications or sandboxed Java applets, which rely on the Java sandbox for security. Successful exploitation may lead to unauthorized access, creation, deletion, or modification of critical data or all data accessible by the software.
Recommendations Update Oracle Java SE version 8u491 to a newer version. Update Oracle Java SE version 8u491-perf to a newer version. Update Oracle Java SE to version 11.0.32 or later.

Fix

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:42877
BIT-JAVA-2026-47058
BIT-JAVA-MIN-2026-47058
BIT-JRE-2026-47058
CVE-2026-47058
OPENSUSE-SU-2026:11335-1
OPENSUSE-SU-2026:11453-1
OPENSUSE-SU-2026:11487-1
SUSE-SU-2026:3284-1
SUSE-SU-2026:3453-1
SUSE-SU-2026:3614-1
SUSE-SU-2026:3615-1
SUSE-SU-2026:3622-1
SUSE-SU-2026:3623-1
USN-8673-1
USN-8674-1

Affected Products

Java Platform
Java Se