CVE-2026-60526 Details
Description
Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).
A vulnerability has been identified in Oracle Java SE, specifically in the Installation component, affecting versions 8u491 and 8u491-perf. This vulnerability allows a low-privileged attacker with access to the environment where Oracle Java SE is running to compromise the application. Exploitation of this issue is difficult and requires human interaction from someone other than the attacker. When successfully exploited, this vulnerability can lead to a complete takeover of Oracle Java SE. The issue can be triggered using APIs within the Installation component, such as through a web service that provides data to these APIs. Additionally, this vulnerability is relevant to Java deployments in clients that execute sandboxed Java Web Start applications or applets, which load untrusted code from the internet and depend on the Java sandbox for security.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| oracle jdk | 1.8.0 update491 |
CPE
Remediation
| |
| oracle jre | 1.8.0 update491 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | Initial Analysis | [email protected] |
| Aug 1, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |