Vulnerability in Oracle Java SE Installation Component Affects Oracle Software
CVE-2026-60526

6.7MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60526?

A vulnerability in the installation component of Oracle Java SE allows low-privileged attackers with logon access to compromise the software. Although challenging to exploit, the vulnerability requires human interaction from an individual other than the attacker. Successful exploitation can lead to the takeover of Oracle Java SE, especially in environments running sandboxed Java applications or applets that execute untrusted code. This poses a significant risk to confidentiality, integrity, and availability of affected systems, particularly when utilizing APIs that connect with external sources.

Affected Version(s)

Oracle Java SE 8u491

Oracle Java SE 8u491-perf

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.