
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47058 is a vulnerability in the Scripting component of Oracle Java SE affecting versions 8u491, 8u491-perf, and 11.0.31. It was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026. The vulnerability allows an unauthenticated remote attacker with network access via multiple protocols to compromise Oracle Java SE, resulting in high confidentiality and integrity impacts. It carries a CVSS v3.1 base score of 7.4 (High) (Oracle CPU July 2026).
The vulnerability resides in the Scripting component of Oracle Java SE and is classified as difficult to exploit (high attack complexity), requiring no privileges or user interaction. It can be triggered through APIs exposed by the Scripting component, for example via a web service that supplies data to those APIs, or through sandboxed Java Web Start applications and Java applets that load untrusted code from the internet and rely on the Java sandbox for security. The flaw was reported to Oracle by researchers 4ra1n, pyn3rd, and unam4, who also reported the related CVEs CVE-2026-47057 and CVE-2026-47064 (Oracle CPU July 2026). No specific CWE classification has been publicly assigned at this time.
Successful exploitation can result in unauthorized creation, deletion, or modification of critical data accessible to Oracle Java SE, as well as unauthorized read access to critical or all accessible data. The vulnerability has high confidentiality and integrity impacts with no availability impact. Environments running sandboxed Java Web Start applications or applets that process untrusted code are particularly at risk, as the sandbox security model may be bypassed (Oracle CPU July 2026).
Oracle strongly recommends applying the July 2026 Critical Patch Update patches as soon as possible. The affected versions are Oracle Java SE 8u491, 8u491-perf, and 11.0.31; users should upgrade to the patched releases provided in the CPU. As a temporary measure, Oracle suggests blocking network protocols required by the attack where feasible, though this may impact application functionality and is not a long-term solution. Oracle also recommends running only actively-supported Java SE versions (Oracle CPU July 2026).
The vulnerability was detected by Qualys (detection ID 387986) and indexed by Tenable shortly after disclosure. No significant public researcher commentary, vendor statements beyond Oracle's advisory, or notable media coverage have been identified at this time (Oracle CPU July 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."