
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47027 is a denial-of-service vulnerability in the Libraries component of Oracle Java SE, disclosed as part of Oracle's Critical Patch Update for July 2026. Affected versions include Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1; Oracle GraalVM for JDK 17.0.19 and 21.0.11; and Oracle GraalVM Enterprise Edition 21.3.18. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium), reflecting a network-accessible, unauthenticated attack path with limited availability impact (Oracle CPU Jul 2026).
The vulnerability resides in the Libraries component of Oracle Java SE and is classified as an availability-impacting flaw (CWE category: partial denial of service). It is easily exploitable by an unauthenticated remote attacker over multiple network protocols, requiring no user interaction or elevated privileges. Exploitation can occur via APIs exposed through web services that supply data to the affected Libraries component, and also applies to sandboxed Java Web Start applications or Java applets that load untrusted code from the internet. No public technical write-up or proof-of-concept code has been identified at this time (Oracle CPU Jul 2026).
Successful exploitation results in a partial denial of service (partial DOS) of Oracle Java SE, affecting availability without any impact to confidentiality or integrity. The attack can be launched remotely without authentication, making it feasible to disrupt Java-based services or applications exposed over a network. The scope is limited to the affected Java SE instance and does not indicate lateral movement potential or data exposure risk (Oracle CPU Jul 2026).
Oracle strongly recommends applying the July 2026 Critical Patch Update patches as soon as possible, which address this vulnerability across all affected Java SE and GraalVM versions. As a temporary measure, Oracle suggests blocking network protocols required by the attack vector where feasible, though this may impact application functionality and is not a long-term solution. Organizations should upgrade to patched releases of Oracle Java SE (beyond 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1) and GraalVM (beyond 17.0.19, 21.0.11 for JDK; 21.3.18 for Enterprise Edition) as provided in the CPU (Oracle CPU Jul 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."