Junglewise Threat Intelligence

CVE-2026-60166: Oracle Java SE information disclosure in JavaFX

CVE-2026-60166 · Severity: low · CVSS 3.1 · Published 2026-07-21

Executive brief

A vulnerability exists in the JavaFX component of Oracle Java SE, which is used for creating desktop and rich internet applications. An attacker could potentially gain unauthorized access to a limited amount of data if a user interacts with malicious content, such as an untrusted website or application. This issue primarily affects desktop users running older Java applets or Web Start applications rather than standard server environments.

Technical details

This vulnerability affects the JavaFX component within Oracle Java SE version 8u491. It is classified as a low-severity information disclosure bug that is difficult to exploit. The attack vector is network-based via multiple protocols, but it requires a user to interact with untrusted code, typically within a sandboxed environment like Java Web Start or a Java applet. A successful exploit results in unauthorized read access to a limited subset of data accessible to the Java runtime. Server-side deployments that only run trusted, administrator-installed code are generally not at risk.

Affected products

  • Oracle Java SE 8u491

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats