Vulnerability in Oracle Java SE Affecting JavaFX Component
CVE-2026-47035

3.1LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47035?

This vulnerability affects Oracle Java SE, specifically its JavaFX component, by allowing an unauthenticated attacker with network access to compromise the system. Successful exploitation necessitates user interaction from an individual other than the attacker, significantly complicating the attack vector. The vulnerability primarily targets Java deployments that run in sandboxed environments, such as Java Web Start applications or Java applets, where untrusted code may be executed. It's important to note that deployments on servers running only trusted code are not impacted. The potential consequences of this vulnerability can include unauthorized modifications to accessible data.

Affected Version(s)

Oracle Java SE 8u491

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.