PT-2026-62218 · Oracle · Java Se+1
CVE-2026-47058
·
Published
2026-07-21
·
Updated
2026-08-25
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE version 8u491
Oracle Java SE version 8u491-perf
Oracle Java SE versions prior to 11.0.32
Description
A flaw in the Scripting component allows an unauthenticated attacker with network access via multiple protocols to compromise the system. This can be achieved by using APIs in the affected component, such as through a web service that provides data to those APIs. The issue also impacts Java deployments that load and run untrusted code, such as sandboxed Java Web Start applications or sandboxed Java applets, which rely on the Java sandbox for security. Successful exploitation may lead to unauthorized access, creation, deletion, or modification of critical data or all data accessible by the software.
Recommendations
Update Oracle Java SE version 8u491 to a newer version.
Update Oracle Java SE version 8u491-perf to a newer version.
Update Oracle Java SE to version 11.0.32 or later.
Fix
DoS
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Java Platform
Java Se