Junglewise Threat Intelligence

CVE-2026-21947: Oracle Java SE XSS in JavaFX

CVE-2026-21947 · Severity: low · CVSS 3.1 · Published 2026-01-20

Technologies: Oracle Java SE, Oracle Jdk, Oracle Java SE (JavaFX), Siemens SIMATIC CN 4100, Oracle JRE. Vendors: Oracle, Siemens.

Executive brief

A vulnerability in the JavaFX component of Oracle Java SE could allow an attacker to perform unauthorized data modifications. This issue primarily affects client-side Java deployments, such as sandboxed web applications or applets that run untrusted code from the internet. To be successful, an attacker must convince a user to interact with a malicious application, making it difficult to exploit in practice.

Technical details

This vulnerability exists in the JavaFX component of Oracle Java SE, specifically affecting version 8u471-b50. It is classified as a Cross-Site Scripting (XSS) vulnerability (CWE-79) by CISA-ADP. The attack is complex (AC:H) and requires human interaction (UI:R) from a user other than the attacker. It primarily impacts the integrity of data within sandboxed Java environments, such as Java Web Start or Java applets, where untrusted code is executed. Successful exploitation allows an attacker to perform unauthorized update, insert, or delete operations on accessible Java SE data. Oracle has addressed this in their January 2026 Critical Patch Update, and Siemens has released updates for affected SIMATIC CN 4100 devices.

Affected products

  • Oracle Java SE (JavaFX) 8u471-b50
  • Siemens SIMATIC CN 4100 All versions < V5.0

Timeline

  • 2026-01-20: disclosed: Initial disclosure by Oracle
  • 2026-01-20: advisory: NVD published CVE-2026-21947
  • 2026-05-12: patched: Siemens released SIMATIC CN 4100 V5.0 to address the vulnerability

References

Related threats