JavaFX Vulnerability in Oracle Java SE Exposes Data to Unauthorized Access
CVE-2026-47034
3.1LOW
What is CVE-2026-47034?
A vulnerability in Oracle Java SE, specifically in the JavaFX component, allows a network-based, unauthenticated attacker to compromise the system. This issue affects version 8u491 and requires human interaction from a third party, making exploitation less straightforward. The vulnerability primarily impacts Java deployments, particularly in scenarios that run sandboxed Java Web Start applications or applets that load untrusted code from the internet. In such deployments, an attacker could gain unauthorized access to update, insert, or delete critical data within Oracle Java SE. It is important to note that this vulnerability does not extend to server deployments running trusted code, thus limiting its risk profile.
Affected Version(s)
Oracle Java SE 8u491