Vulnerability in Oracle Java SE Scripting Component
CVE-2026-47058

7.4HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47058?

A vulnerability exists in the Scripting component of Oracle Java SE, allowing unauthenticated attackers with network access to exploit the system via various protocols. This flaw can lead to unauthorized creation, deletion, or modification of critical data. It affects versions 8u491, 8u491-perf, and 11.0.31 and can be exploited through APIs, making it a significant risk for users running sandboxed Java Web Start applications or Java applets that execute untrusted code. Proper security measures should be implemented to mitigate potential risks.

Affected Version(s)

Oracle Java SE 8u491

Oracle Java SE 8u491-perf

Oracle Java SE 11.0.31

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.