CVE-2026-47058
OpenJDK JDK vulnerability analysis and mitigation

Overview

CVE-2026-47058 is a vulnerability in the Scripting component of Oracle Java SE affecting versions 8u491, 8u491-perf, and 11.0.31. It was disclosed on July 21, 2026, as part of Oracle's Critical Patch Update (CPU) for July 2026. The vulnerability allows an unauthenticated remote attacker with network access via multiple protocols to compromise Oracle Java SE, resulting in high confidentiality and integrity impacts. It carries a CVSS v3.1 base score of 7.4 (High) (Oracle CPU July 2026).

Technical details

The vulnerability resides in the Scripting component of Oracle Java SE and is classified as difficult to exploit (high attack complexity), requiring no privileges or user interaction. It can be triggered through APIs exposed by the Scripting component, for example via a web service that supplies data to those APIs, or through sandboxed Java Web Start applications and Java applets that load untrusted code from the internet and rely on the Java sandbox for security. The flaw was reported to Oracle by researchers 4ra1n, pyn3rd, and unam4, who also reported the related CVEs CVE-2026-47057 and CVE-2026-47064 (Oracle CPU July 2026). No specific CWE classification has been publicly assigned at this time.

Impact

Successful exploitation can result in unauthorized creation, deletion, or modification of critical data accessible to Oracle Java SE, as well as unauthorized read access to critical or all accessible data. The vulnerability has high confidentiality and integrity impacts with no availability impact. Environments running sandboxed Java Web Start applications or applets that process untrusted code are particularly at risk, as the sandbox security model may be bypassed (Oracle CPU July 2026).

Mitigation and workarounds

Oracle strongly recommends applying the July 2026 Critical Patch Update patches as soon as possible. The affected versions are Oracle Java SE 8u491, 8u491-perf, and 11.0.31; users should upgrade to the patched releases provided in the CPU. As a temporary measure, Oracle suggests blocking network protocols required by the attack where feasible, though this may impact application functionality and is not a long-term solution. Oracle also recommends running only actively-supported Java SE versions (Oracle CPU July 2026).

Community reactions

The vulnerability was detected by Qualys (detection ID 387986) and indexed by Tenable shortly after disclosure. No significant public researcher commentary, vendor statements beyond Oracle's advisory, or notable media coverage have been identified at this time (Oracle CPU July 2026).

Additional resources


SourceThis report was generated using AI

Related OpenJDK JDK vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47063HIGH7.5
  • OpenJDK JDK logoOpenJDK JDK
  • java-21-openjdk-static-libs-slowdebug
NoYesJul 21, 2026
CVE-2026-47057HIGH7.5
  • OpenJDK JDK logoOpenJDK JDK
  • openjdk-11
NoYesJul 21, 2026
CVE-2026-47058HIGH7.4
  • OpenJDK JDK logoOpenJDK JDK
  • java-1.8.0-openjdk-devel-slowdebug
NoYesJul 21, 2026
CVE-2026-60147MEDIUM6.5
  • OpenJDK JDK logoOpenJDK JDK
  • java-21-openjdk-devel
NoYesJul 21, 2026
CVE-2026-47059LOW3.7
  • OpenJDK JDK logoOpenJDK JDK
  • java-1.8.0-openjdk-demo-slowdebug
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management