Description
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the JavaFX component of Oracle Java SE 8u491, classified as a CWE‑284 Access Control Failure, renders the sandbox ineffective. An unauthenticated attacker with network access can attempt exploitation, but a separate human interaction from a third party is required for a successful compromise. When achieved, the attacker can manipulate, insert, or delete data that the Java application has access to, impacting the integrity of that data. No confidentiality or availability impact is reported.

Affected Systems

The flaw affects Oracle Java SE 8u491, specifically those client deployments that rely on the Java sandbox for security, such as Java Web Start applications and sandboxed applets that load code from the internet. Server deployments that only run trusted code are not impacted.

Risk and Exploitability

The CVSS v3.1 base score of 3.1 reflects a low to moderate risk, with a high complexity but only requiring network access. The EPSS score indicates a probability of approximately 0.2 % and the vulnerability is not listed in CISA’s KEV catalog. The requirement for a separate human interaction and the need to exploit the JavaFX sandbox make widespread exploitation unlikely, but the integrity consequences for affected client systems remain a concern.

Generated by OpenCVE AI on August 4, 2026 at 05:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched Oracle Java SE version (8u492 or newer) that addresses the JavaFX sandbox flaw.
  • If an immediate upgrade is not possible, isolate the Java environments by restricting network access to trusted networks, disabling Java Web Start or sandboxed applets where feasible, and ensuring only trusted code is executed.
  • Monitor logs for anomalous data modification activity associated with JavaFX and apply any interim security updates from Oracle as they become available.

Generated by OpenCVE AI on August 4, 2026 at 05:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title JavaFX Access Control Failure in Oracle Java SE 8u491

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title JavaFX Access Control Failure in Oracle Java SE 8u491

Mon, 27 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title JavaFX Sandbox Escape in Oracle Java SE 8u491 Allows Integrity Compromise in Client Deployments

Fri, 24 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title JavaFX Sandbox Escape in Oracle Java SE 8u491 Allows Integrity Compromise in Client Deployments

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle java Se
CPEs cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle java Se
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:06:59.696Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47034

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:29.232Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:08.943

Modified: 2026-08-03T18:53:50.320

Link: CVE-2026-47034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses