
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47059 is a vulnerability in the 2D component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition, disclosed as part of Oracle's July 2026 Critical Patch Update. Affected versions include Oracle Java SE 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1; Oracle GraalVM for JDK 17.0.19 and 21.0.11; and Oracle GraalVM Enterprise Edition 21.3.18. The vulnerability was reported by researcher BBBBear and published on July 21, 2026. It carries a CVSS v3.1 base score of 3.7 (Low severity) (Oracle CPU Jul 2026).
The vulnerability resides in the 2D component of Oracle Java SE and related products, and is exploitable by an unauthenticated remote attacker via multiple network protocols. Exploitation requires high attack complexity, meaning specific conditions must be met, and no privileges or user interaction are required. The vulnerability specifically applies to Java deployments running sandboxed Java Web Start applications or sandboxed Java applets that load and execute untrusted code from the internet; server-side deployments running only trusted code are not affected. No CWE classification or detailed technical write-up has been publicly disclosed at this time (Oracle CPU Jul 2026).
Successful exploitation can result in a partial denial of service (partial DOS) affecting the availability of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition. There is no impact to confidentiality or integrity. The scope of impact is limited to the affected Java runtime environment, and the vulnerability does not enable code execution, data exfiltration, or lateral movement (Oracle CPU Jul 2026).
Oracle strongly recommends applying the July 2026 Critical Patch Update patches as soon as possible. The patched versions for Oracle Java SE are those released after 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, and 26.0.1; similarly, GraalVM for JDK and GraalVM Enterprise Edition users should apply the corresponding CPU patches. As a temporary measure, blocking network protocols required by the attack or restricting access to sandboxed Java Web Start and applet environments may reduce risk, though Oracle notes these are not long-term solutions. Organizations not using sandboxed Java Web Start applications or applets are not affected by this vulnerability (Oracle CPU Jul 2026).
The vulnerability was detected by Qualys scanners and noted in Tenable's plugin pipeline shortly after disclosure, indicating routine uptake by vulnerability management vendors. No notable researcher commentary, media coverage, or significant community discussion has been identified beyond standard CPU tracking, consistent with the low severity rating of this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."