Description
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the JavaFX component of Oracle Java SE allows an unauthenticated network attacker to compromise a Java execution environment that runs sandboxed untrusted code, such as Java Web Start applications or applets. The flaw requires human interaction from a user other than the attacker but can lead to unauthorized update, insert or delete operations on data accessible through the Java application, thereby impacting data integrity.

Affected Systems

Oracle Java SE 8u491, is affected. This product is used in client machines that run sandboxed Java Web Start applications or Java applets which load code from external sources such as the Internet. Server-side deployments that run only trusted code are not impacted by this vulnerability.

Risk and Exploitability

The vulnerability has a CVSS v3.1 base score of 3.1, indicating a low integrity impact. The EPSS score is less than 1 %, suggesting a very low likelihood of exploitation in the wild, and it is not listed in CISA’s KEV catalog. The attack likely occurs over network protocols that allow the delivery of untrusted Java code to a client. An attacker must first convince or coerce a user to run such a program, which reduces the practical risk to systems that regularly enforce strict download and execution policies.

Generated by OpenCVE AI on August 4, 2026 at 05:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Java SE to the latest patched version available from Oracle.
  • Disable or uninstall Java Web Start and other sandboxed Java plug‑in mechanisms if not required.
  • Restrict network access that allows downloading or executing Java Web Start applications or applets, and enforce strict application whitelisting policies.

Generated by OpenCVE AI on August 4, 2026 at 05:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title JavaFX Component Improper Access Control Allowing Unauthorized Data Modification

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title JavaFX Sandbox Bypass Allows Unauthorized Data Modification

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title JavaFX Sandbox Bypass Allows Unauthorized Data Modification

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle java Se
CPEs cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle java Se
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:06:50.911Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47035

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:30.931Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:09.060

Modified: 2026-08-03T18:53:27.363

Link: CVE-2026-47035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses