Description
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Oracle Java SE version 8u491 within the JavaFX component and permits an unauthenticated attacker with network access to read a restricted subset of data from the Java runtime. The attack requires interaction from a third party beyond the attacker and does not provide higher privileges or denial of service. The impact is strictly confidentiality‑only, as noted by the CVSS vector showing a low confidentiality impact and no impact on integrity or availability.

Affected Systems

Affected deployments are Oracle Java SE on client systems that rely on the sandbox to isolate untrusted Java Web Start applications or applets, typically those that execute code downloaded from the internet. Server side deployments that only run trusted, administrator‑installed code are not within the scope of the vulnerability.

Risk and Exploitability

The CVSS score of 3.1 indicates a low‑severity risk, and the EPSS score of less than 1% shows a very low probability of exploitation under current conditions. The vulnerability does not appear in the CISA KEV catalog. Exploitation requires the attacker to entice a user into interacting with a piece of untrusted Java code that can then read sandboxed data. Because of the high attack complexity and the need for user‑initiated action, the overall risk to exposed users is modest, but the presence of a confidentiality breach makes remediation advisable.

Generated by OpenCVE AI on August 4, 2026 at 04:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Java SE to the latest version that includes the July 2026 security patch for the JavaFX component, which removes the ability of untrusted code to read protected data.
  • Disable or restrict the use of Java Web Start applications and Java applets in client environments, or enforce strict sandbox policies that prevent untrusted code from reading local data.
  • If an update cannot be applied immediately, isolate affected clients from network paths that allow downloading untrusted Java code, and block protocols that can be used to deliver the exploit (e.g., HTTP/HTTPS to known risk sites).

Generated by OpenCVE AI on August 4, 2026 at 04:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Oracle Java SE JavaFX Vulnerability Allows Untrusted Code to Read Sandbox Data

Tue, 28 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title JavaFX Unauthenticated Data Read in Oracle Java SE 8u491
Weaknesses CWE-200
CWE-285

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title JavaFX Unauthenticated Data Read in Oracle Java SE 8u491
Weaknesses CWE-200
CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle java Se
CPEs cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle java Se
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:21:19.686Z

Reserved: 2026-07-08T15:51:40.516Z

Link: CVE-2026-60164

cve-icon Vulnrichment

Updated: 2026-07-23T15:21:11.516Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure