CVE-2026-47013: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. in Oracle Corporation Oracle Java SE
CVE-2026-47013 is a vulnerability in Oracle Java SE 8u491, specifically in the JavaFX component. It allows an unauthenticated attacker with network access via multiple protocols to cause a partial denial of service (partial DOS) of Oracle Java SE. The vulnerability can be exploited through APIs, including those used by sandboxed Java Web Start applications or applets running untrusted code. The CVSS 3.1 base score is 5.3, indicating a medium severity impact focused on availability.
AI Analysis
Technical Summary
This vulnerability affects Oracle Java SE version 8u491 in the JavaFX component. An unauthenticated attacker with network access can exploit this issue via multiple protocols to cause a partial denial of service condition. The attack vector involves using APIs exposed by the component, including scenarios where sandboxed Java Web Start applications or applets load untrusted code and rely on the Java sandbox for security. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, reflecting network attack vector, low complexity, no privileges or user interaction required, and impact limited to availability (partial DOS). No confidentiality or integrity impacts are noted. The vulnerability is identified as CWE-770 (Allocation of Resources Without Limits or Throttling).
Potential Impact
Successful exploitation results in unauthorized ability to cause a partial denial of service of Oracle Java SE, impacting availability. There is no impact on confidentiality or integrity. The vulnerability can be triggered remotely without authentication or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The Oracle Critical Patch Update Advisory for July 2026 does not explicitly list a patch for this specific vulnerability. Oracle strongly recommends applying security patches promptly when available and remaining on actively supported versions. Until a patch is released, consider limiting network exposure of affected Java SE 8u491 deployments and avoid running untrusted code in sandboxed Java environments if possible.
CVE-2026-47013: Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE. in Oracle Corporation Oracle Java SE
Description
CVE-2026-47013 is a vulnerability in Oracle Java SE 8u491, specifically in the JavaFX component. It allows an unauthenticated attacker with network access via multiple protocols to cause a partial denial of service (partial DOS) of Oracle Java SE. The vulnerability can be exploited through APIs, including those used by sandboxed Java Web Start applications or applets running untrusted code. The CVSS 3.1 base score is 5.3, indicating a medium severity impact focused on availability.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects Oracle Java SE version 8u491 in the JavaFX component. An unauthenticated attacker with network access can exploit this issue via multiple protocols to cause a partial denial of service condition. The attack vector involves using APIs exposed by the component, including scenarios where sandboxed Java Web Start applications or applets load untrusted code and rely on the Java sandbox for security. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, reflecting network attack vector, low complexity, no privileges or user interaction required, and impact limited to availability (partial DOS). No confidentiality or integrity impacts are noted. The vulnerability is identified as CWE-770 (Allocation of Resources Without Limits or Throttling).
Potential Impact
Successful exploitation results in unauthorized ability to cause a partial denial of service of Oracle Java SE, impacting availability. There is no impact on confidentiality or integrity. The vulnerability can be triggered remotely without authentication or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The Oracle Critical Patch Update Advisory for July 2026 does not explicitly list a patch for this specific vulnerability. Oracle strongly recommends applying security patches promptly when available and remaining on actively supported versions. Until a patch is released, consider limiting network exposure of affected Java SE 8u491 deployments and avoid running untrusted code in sandboxed Java environments if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- oracle
- Date Reserved
- 2026-05-18T15:55:10.317Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://www.oracle.com/security-alerts/cpujul2026.html","vendor":"Oracle"}]
Threat ID: 6a5fe6c89c2644c7f8cb0777
Added to database: 07/21/2026, 21:38:16 UTC
Last enriched: 07/30/2026, 04:55:12 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.