Impact
CVE-2026-47063 is a vulnerability in the libraries component of Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition that allows an unauthenticated attacker with network access to create, delete, or modify critical data by exploiting unsafe jar handling. The weakness is modeled by CWE-347 and results in a high integrity impact without affecting confidentiality or availability. The vulnerability can be triggered through exposed APIs that load JAR files, including web services and sandboxed Java client applications that download code from the internet.
Affected Systems
Affected products include Oracle Java SE up to versions 8u491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1, and 8u491-perf; Oracle GraalVM for JDK 17.0.19 and 21.0.11; and Oracle GraalVM Enterprise Edition 21.3.18. Any system that hosts or runs Java applications using these components and exposes the vulnerable APIs to a network is susceptible.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a moderate to high risk, while the EPSS score of less than 1% suggests that, so far, few exploits have been observed. The vulnerability is not listed in the CISA KEV catalog, but it is still considered easily exploitable for remote attackers. An unauthenticated attacker can send crafted requests over the network to any service that processes JAR files or invokes the vulnerable API, thereby achieving unauthorized changes to application data.
OpenCVE Enrichment
Debian DLA
Debian DSA