JavaFX Vulnerability in Oracle Java SE Affects Multiple Protocols
CVE-2026-47030

3.1LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47030?

A vulnerability exists in Oracle Java SE's JavaFX component that allows unauthenticated attackers with network access to exploit affected systems. This issue, primarily impacting Oracle Java SE version 8u491, can lead to unauthorized updates, inserts, or deletions of data when untrusted code is executed within the Java sandbox environment. To successfully exploit this vulnerability, an attacker must entice a user to interact with the malicious code, thus bypassing Java's security measures that typically protect against untrusted sources. It is crucial for users to ensure that their Java deployments, especially those running sandboxed applications or applets, are regularly updated to mitigate associated risks.

Affected Version(s)

Oracle Java SE 8u491

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.