Description
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the JavaFX component of Oracle Java SE exposes a sandbox bypass that lets an unauthenticated attacker with network reach affect the integrity of data handled by the Java runtime. The flaw permits unauthorized update, insert or delete operations on data accessible to Java applications, indicating an improper access control weakness (CWE‑284). Successful exploitation requires a degree of human interaction with a third party and does not allow for full remote code execution, but the impact on confidentiality is minimal, while the integrity impact can be significant for software relying on the sandbox for protection.

Affected Systems

The affected platform is Oracle Java SE 8u491, specifically its client deployments that run sandboxed Java Web Start applications or applets loading untrusted code from the internet. Server deployments that execute only trusted, administrator‑installed code are not impacted. The precise version listing, 8u491, is the only affected build in the product line documented by Oracle.

Risk and Exploitability

The CVSS score of 3.1 indicates a low severity, and the EPSS score of less than 1%, combined with its absence from the CISA KEV catalog, suggest a low likelihood of widespread, automated exploitation. The likely attack vector is through network protocols that a sandboxed Java application may use to fetch and execute code; the attacker must also involve a human user who supplies or accepts the malicious content. Because exploitation requires interaction and does not grant full remote code execution, the real world risk is primarily confined to integrity loss for sandboxed deployments, especially where untrusted code is routinely downloaded.

Generated by OpenCVE AI on August 4, 2026 at 05:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review all Oracle Java SE 8u491 installations and disable the use of Java Web Start and Java applets when untrusted code is not required.
  • Restrict network access for JavaFX applications by firewalling or limiting the protocols and ports used for loading external resources.
  • Plan to upgrade to a newer Java SE release or apply Oracle’s latest security patch when it becomes available, ensuring that all sandboxed components are protected against known weaknesses.

Generated by OpenCVE AI on August 4, 2026 at 05:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title JavaFX Sandbox Bypass Allows Unauthenticated Integrity Modification in Oracle Java SE 8u491

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title JavaFX Sandbox Bypass Allows Unauthenticated Integrity Modification in Oracle Java SE 8u491

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title JavaFX Sandbox Bypass Allowing Unauthorized Data Modification
Weaknesses CWE-269

Fri, 24 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title JavaFX Sandbox Bypass Allowing Unauthorized Data Modification
Weaknesses CWE-269

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle java Se
CPEs cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle java Se
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:07:31.945Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47030

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:26.204Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses