CVE-2026-47027
Analyzed Analyzed - Analysis Complete

Oracle Java SE Partial Denial of Service Vulnerability

Vulnerability report for CVE-2026-47027, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-21

Last updated on: 2026-08-03

Assigner: Oracle

Description

Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-21
Last Modified
2026-08-03
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-09
NVD
EUVD

Affected Vendors & Products

Showing 17 associated CPEs
Vendor Product Version / Range
oracle graalvm 21.3.18
oracle graalvm_for_jdk 17.0.19
oracle graalvm_for_jdk 21.0.11
oracle jre 1.8.0
oracle jre 11.0.31
oracle jre 17.0.19
oracle jre 21.0.11
oracle jre 25.0.3
oracle jre 26.0.1
oracle jre 1.8.0
oracle jdk 1.8.0
oracle jdk 11.0.31
oracle jdk 17.0.19
oracle jdk 21.0.11
oracle jdk 25.0.3
oracle jdk 26.0.1
oracle jdk 1.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a vulnerability in Oracle Java SE and GraalVM components. It allows unauthenticated attackers with network access to cause a partial denial of service (DOS) in affected versions. The issue stems from weaknesses in the Libraries component and can be exploited via multiple protocols or APIs, including web services or sandboxed Java applications.

Detection Guidance

Detection requires checking installed Java versions against affected releases. Use commands like 'java -version' to identify installed versions. Compare output against Oracle Java SE 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1 and GraalVM versions 17.0.19, 21.0.11, 21.3.18.

Impact Analysis

The vulnerability can lead to partial disruptions in Java SE services, causing downtime or reduced availability. Systems running vulnerable versions of Oracle Java SE, GraalVM for JDK, or GraalVM Enterprise Edition are at risk. Attackers could exploit it to degrade performance without needing authentication.

Compliance Impact

This vulnerability causes a partial denial of service in Oracle Java SE, which could disrupt availability of systems processing sensitive data. For GDPR, this may impact data availability requirements under Article 32. For HIPAA, it could affect system availability for protected health information processing.

Mitigation Strategies

Apply Oracle's security patches immediately for affected Java versions. If patches are unavailable, consider downgrading to a non-affected version or disabling Java in web browsers and applications until updates are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47027. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart