Executive brief
A vulnerability exists in the Scripting component of Oracle Java SE, a widely used platform for running business applications. An attacker could exploit this flaw to gain unauthorized access to sensitive data or modify critical information. This issue is particularly relevant for systems that process data from external web services or run untrusted code in sandboxed environments like Java Web Start.
Technical details
A vulnerability in the Scripting component of Oracle Java SE (versions 8u491 and 11.0.31) allows unauthenticated attackers to compromise the environment via multiple network protocols. The exploit is characterized as high complexity (AC:H), often requiring the use of specific APIs within the Scripting component, such as through a web service that supplies malicious data to those APIs. Successful exploitation can lead to unauthorized creation, deletion, or modification of all Java-accessible data, as well as complete confidentiality loss. This also impacts client-side deployments running sandboxed Java Web Start applications or applets that execute untrusted code. Users should apply the July 2026 Oracle Critical Patch Update.
Affected products
- Oracle Java SE 8u491, 8u491-perf, 11.0.31
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory