Sceawere

Vulnerability Detail

CVE-2026-70906UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Java SE 2D DoS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Java SE
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 25.0.4 and 26.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-18T21:17:48.393Z",
  "pubdate": "2026-08-18T21:17:48.393Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the 2D component of Oracle Java SE, specifically affecting versions 25.0.4 and 26.0.2. This vulnerability allows an unauthenticated remote attacker with network access via multiple protocols to compromise the affected software, resulting in complete denial of service (DoS) conditions through application hangs or frequently repeatable crashes. The flaw can be weaponized using APIs within the 2D component, such as through web services that supply untrusted data to these APIs. Additionally, the vulnerability impacts Java deployments—typically clients running sandboxed Java Web Start applications or sandboxed Java applets—that load and execute untrusted code from external sources while relying on the Java sandbox for security boundaries. With a CVSS 3.1 Base Score of 7.5 and a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, the risk implications are significant due to the lack of required authentication, user interaction, or elevated privileges, making network-based exploitation straightforward for malicious actors targeting service availability.",
  "technicalDetails": "The vulnerability resides in the 2D component of Oracle Java SE, impacting versions 25.0.4 and 26.0.2. The root cause stems from improper handling of data passed to the component's APIs, which can be triggered remotely without requiring prior authentication (PR:N) or user interaction (UI:N). The attack vector is network-based (AV:N) with low attack complexity (AC:L), allowing threat actors to leverage multiple network protocols to deliver maliciously crafted payloads.\nExploitation occurs step-by-step as follows: First, the attacker identifies an exposed endpoint or interface that interacts with the vulnerable 2D component APIs, such as a web service processing client-supplied data or a sandboxed client execution context (e.g., Java Web Start applications or Java applets loading untrusted code from the internet). Second, the attacker transmits a specially crafted payload via network protocols to the target system. Third, the vulnerable 2D component parses or processes the malformed input data. Due to inadequate validation or exception handling within the component, processing the payload triggers a fatal error, resource exhaustion, or an unhandled exception.\nThe payload behavior directly results in disruption of service execution threads, leading to an unauthorized ability to cause a hang or a frequently repeatable crash of the Oracle Java SE runtime environment. The scope remains unchanged (S:U) as the impact is confined to the availability of the affected Java SE instance (A:H), with no direct impact on confidentiality (C:N) or integrity (I:N). Post-exploitation impact is strictly limited to denial of service, as the flaw does not grant remote code execution or unauthorized data access privileges."
}
CVE-2026-70906: Oracle Java SE 2D DoS Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere