Junglewise Threat Intelligence

CVE-2026-60164: Oracle Java SE information disclosure in JavaFX

CVE-2026-60164 · Severity: low · CVSS 3.1 · Published 2026-07-21

Technologies: Oracle Java SE (JavaFX). Vendors: Oracle.

Executive brief

A vulnerability exists in the JavaFX component of Oracle Java SE, which is used for creating desktop and rich internet applications. This flaw could allow an attacker to gain unauthorized access to a limited amount of data on a user's computer if the user interacts with a malicious application or website. This issue primarily affects desktop users running older Java applets or Web Start applications that execute untrusted code from the internet.

Technical details

A vulnerability in the JavaFX component of Oracle Java SE 8u491 allows an unauthenticated attacker with network access via multiple protocols to compromise the environment. The flaw is specifically relevant to client-side deployments, such as sandboxed Java Web Start applications or applets that run untrusted code. Successful exploitation requires user interaction (UI:R) and faces high attack complexity (AC:H). If exploited, the attacker can achieve unauthorized read access (Confidentiality: Low) to a subset of data accessible by the Java process. Server-side deployments that only run trusted code are generally not affected.

Affected products

  • Oracle Java SE (JavaFX) 8u491

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats