Executive brief
A vulnerability exists in the JavaFX component of Oracle Java SE, which is used for creating desktop and rich internet applications. An attacker could potentially modify or delete certain data if a user interacts with malicious content, such as a compromised website or untrusted application. This issue primarily affects client-side environments like web browsers running Java applets rather than standard server configurations.
Technical details
This vulnerability affects the JavaFX component within Oracle Java SE version 8u491. It is classified as a low-severity integrity issue (CVSS 3.1 score of 3.1) that is difficult to exploit. The attack vector is network-based and requires an unauthenticated user to interact with malicious content, typically within a sandboxed environment like Java Web Start or a Java applet. A successful exploit allows an attacker to perform unauthorized updates, insertions, or deletions of data accessible to the Java runtime. Server-side deployments running only trusted code are generally not impacted.
Affected products
- Oracle Java SE (JavaFX) 8u491
Timeline
- 2026-07-21: advisory: Oracle published the security alert.
- 2026-07-21: disclosed: CVE-2026-47035 was published to the NVD.