Description
Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Java SE 8u491 release contains a weakness in the JavaFX component that can, if successfully exploited, allow an unauthenticated attacker to read a limited set of data stored within the Java runtime. This flaw is difficult to exploit and requires a separate user to interact with a sandboxed client‑side application; the vulnerability does not affect server deployments that run only trusted code. Based on the description, the impact is confined to confidentiality, allowing the attacker to see data that the Java sandbox was intended to protect, such as credentials or configuration files, without affecting integrity or availability.

Affected Systems

The vulnerability applies to clients running Oracle Java SE 8 update 491 that execute sandboxed Java Web Start applications or applets. Deployments that load only trusted code on servers, as is typically configured, are not affected. Administrators should confirm that their installations match the affected version and that no client‑side sandboxed applications rely on the vulnerable JavaFX classes. The scope is limited to those environments that use JavaFX from untrusted sources.

Risk and Exploitability

With a CVSS score of 3.1 and an EPSS value of less than 1 %, the likelihood of real‑world exploitation is very low, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves network access via the Java Runtime's multiple protocols, combined with a required secondary user interaction. Based on the description, it is inferred that successful exploitation would require an attacker to supply a malicious payload to a sandboxed client, trigger the flaw, and have a distinct user execute the application, thereby constraining the attack surface.

Generated by OpenCVE AI on August 4, 2026 at 04:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Java SE to a version that includes the JavaFX fix, such as the latest update for Java 8.
  • Disable or uninstall Java Web Start and Java applet support on client machines if those features are not required, reducing the exposed surface area.
  • Configure firewall or network segmentation rules to restrict the network protocols that the vulnerable JavaFX component may use, limiting external reach to the JRE.

Generated by OpenCVE AI on August 4, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title JavaFX Data Disclosure Vulnerability in Oracle Java SE 8

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title JavaFX Data Disclosure Vulnerability in Oracle Java SE 8

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title JavaFX Component Vulnerability Allowing Unauthorized Data Read in Oracle Java SE 8u491

Fri, 24 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title JavaFX Component Vulnerability Allowing Unauthorized Data Read in Oracle Java SE 8u491

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Java SE (component: JavaFX). The supported version that is affected is Oracle Java SE: 8u491. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle java Se
CPEs cpe:2.3:a:oracle:java_se:8u491:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle java Se
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:10:46.494Z

Reserved: 2026-07-08T15:51:40.516Z

Link: CVE-2026-60166

cve-icon Vulnrichment

Updated: 2026-07-23T15:10:36.757Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure