CVE-2026-47058 — java
CVE-2026-47058 is a Deserialization of Untrusted Data vulnerability in java. A fix is available for java — see the affected versions and patch details below.
Exploitation Status
No confirmed exploitation observed yet
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-47058.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
javaReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Bitnami packages — download data is not available via public APIs for these ecosystems.
Description
Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf and 11.0.31. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦Bitnami | java | ≥ 1.9.0&&< 1.8.0 | 1.8.0 |
Affected Products
jdkoraclejreoracleDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for java, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update java to 1.8.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-47058 is resolved across your whole dependency graph.
Workarounds
Do not deserialise data from untrusted sources: where the format allows it, restrict deserialisation to an explicit allowlist of expected types, and prefer a data-only format (JSON, Protobuf) over one that can reconstruct arbitrary objects until you can upgrade.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
| Product | Fixed in | Advisory |
|---|---|---|
| OPENJDK ELS 11.0.32 | java-11-openjdk-portable | RHSA-2026:42881 |
| OPENJDK ELS 11.0.32 | java-11-openjdk-windows | RHSA-2026:42882 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | java-1.8.0-openjdk-1:1.8.0.502.b07-1.1.el7_9 | RHSA-2026:42876 |
| Red Hat Enterprise Linux 8 | java-1.8.0-openjdk-1:1.8.0.502.b07-1.1.el8 | RHSA-2026:42877 |
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10 | RHSA-2026:52949 |
| Red Hat OpenJDK 11 els for RHEL 7 | java-11-openjdk-1:11.0.32.0.9-1.el7_9 | RHSA-2026:42880 |
Frequently Asked Questions
Is CVE-2026-47058 in your dependencies?
Find it across Bitnami, including transitive dependencies.