Executive brief
A vulnerability exists in the JavaFX component of Oracle Java SE, which is used for creating desktop and rich internet applications. An attacker could potentially modify or delete certain data within the Java environment if a user interacts with malicious content, such as an untrusted web applet. This issue primarily affects client-side deployments that run sandboxed applications from the internet rather than secure server environments.
Technical details
This vulnerability affects the JavaFX component within Oracle Java SE version 8u491. It is classified as a low-severity integrity issue where an unauthenticated attacker can achieve unauthorized update, insert, or delete access to some Java SE accessible data. The attack vector is network-based but requires high complexity and user interaction, typically involving a victim running a sandboxed Java Web Start application or applet containing untrusted code. Server-side deployments running only trusted code are generally not impacted. The vulnerability was disclosed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Java SE 8u491
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD