Junglewise Threat Intelligence

CVE-2026-47057: Oracle Java SE denial of service in Scripting component

CVE-2026-47057 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle Java SE. Vendors: Oracle.

Executive brief

A vulnerability in the Scripting component of Oracle Java SE allows an unauthenticated attacker to remotely crash the software. This affects applications that use Java to process external data or run untrusted code, such as web services or sandboxed desktop applications. An exploit could lead to a complete denial of service, causing business operations to halt or applications to become unresponsive.

Technical details

This vulnerability exists within the Scripting component of Oracle Java SE. It is classified as a denial-of-service (DoS) flaw that can be triggered by an unauthenticated attacker with network access via multiple protocols. The root cause involves improper handling of data supplied to Scripting APIs, which can lead to a repeatable crash or a system hang. The vulnerability is particularly relevant for Java deployments that load untrusted code (like Java Web Start) or web services that pass external data directly to the affected APIs. Affected versions include 8u491, 8u491-perf, and 11.0.31. Users should refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle Java SE 8u491, 8u491-perf, 11.0.31

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats