Executive brief
A vulnerability exists in the JavaFX component of Oracle Java SE, which is used for creating desktop and rich internet applications. This flaw primarily affects client-side environments, such as those running sandboxed Java Web Start applications or applets that execute code from the internet. If exploited, an attacker could potentially modify or delete certain data, though the attack is difficult to perform and requires a user to interact with a malicious link or application.
Technical details
This vulnerability affects the JavaFX component of Oracle Java SE version 8u491. It is classified as a low-severity integrity issue that is difficult to exploit (High Attack Complexity). The attack vector is network-based and requires human interaction, typically involving a user running untrusted code within a sandboxed environment like Java Web Start or a Java applet. A successful exploit allows an unauthenticated attacker to perform unauthorized updates, insertions, or deletions of data accessible to the Java runtime. Server-side deployments that only run trusted code are generally not affected.
Affected products
- Oracle Java SE (JavaFX) 8u491
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD