JSSE Vulnerability in Oracle Java SE Products
CVE-2026-46968

5.9MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-46968?

A vulnerability exists in Oracle Java SE's JSSE component that could be exploited by an unauthenticated attacker with network access via TLS. This flaw allows for the potential unauthorized creation, deletion, or modification of critical data across various supported versions of Oracle Java SE. The exploitation requires that input be provided to APIs in the JSSE component without leveraging untrusted Java Web Start applications or untrusted applets. Organizations using affected versions should prioritize patching to mitigate the risk of data compromise.

Affected Version(s)

Oracle Java SE 8u491

Oracle Java SE 8u491-perf

Oracle Java SE 11.0.31

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.