{"id":"CVE-2026-59889","title":"com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties (CVE…","summary":"A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to w…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cvssSource":"vendor","cwe":["CWE-915","CWE-863"],"vendor":"Red Hat","product":"Red Hat JBoss EAP 7.4 ELS for RHEL 8","affected":["exploit_intelligence","openshift_developer_tools_and_services","openshift_serverless","ai_inference_server","amq_broker 7","ansible_automation_platform 2","build_of_apache_camel_4_for_quarkus 3","build_of_apache_camel_for_spring_boot 4","build_of_apicurio_registry 3","build_of_debezium 3","build_of_keycloak","build_of_quarkus","ceph_storage 6","ceph_storage 7","ceph_storage 8","ceph_storage 9","certificate_system 10","certificate_system 11","data_grid 8","enterprise_linux 10","enterprise_linux 8","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","fuse 7","jboss_enterprise_application_platform 8","jboss_enterprise_application_platform_expansion_pack","jboss_web_server 7","lightspeed_for_runtimes_operator","offline_knowledge_portal","openshift_ai_rhoai","openshift_dev_spaces","satellite 6","single_sign_on 7","jboss_eap_7_4_els_for_rhel_7_server","jboss_eap_7_4_els_for_rhel 8","jboss_eap_7_4_els_for_rhel 9"],"patched":["jboss_eap_7_4_els_for_rhel_7_server","jboss_eap_7_4_els_for_rhel 8","jboss_eap_7_4_els_for_rhel 9"],"published":"2026-07-14","updated":"2026-09-15","sourceUpdated":"2026-09-15T15:04:51+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59889.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59889.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59889"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500653"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59889"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59889"},{"url":"https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b"},{"url":"https://github.com/FasterXML/jackson-databind/issues/6060"},{"url":"https://github.com/FasterXML/jackson-databind/pull/6056"},{"url":"https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh"},{"url":"https://access.redhat.com/errata/RHSA-2026:67604"},{"url":"https://github.com/advisories/GHSA-5gvw-p9qm-jgwh"}],"tags":["csaf","vex","red-hat","ghsa","maven"],"epss":0.00346,"epssPercentile":0.28129,"aliases":["GHSA-5gvw-p9qm-jgwh"],"ecosystem":"maven","ingestedAt":"2026-07-21T22:55:08.724Z","slug":"CVE-2026-59889","body":"## Overview\n\nA flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to write data to a property annotated with both @JsonView and @JsonUnwrapped even when deserializing under a less-privileged view. This can lead to mass-assignment and privilege escalation, enabling an untrusted caller to modify sensitive data that should be restricted to privileged users.\n\n## Vendor advisories\n\n- **RHSA-2026:67604** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server, Red Hat JBoss EAP 7.4 ELS for RHEL 8, Red Hat JBoss EAP 7.4 ELS for RHEL 9 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67604)\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat AI Inference Server, Red Hat AMQ Broker 7, Red Hat Ansible Automation Platform 2, … · no fix planned: Exploit Intelligence, OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat AI Inference Server, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59889.json)\n\n**com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties** — rated Moderate by Red Hat. Released 2026-07-14, updated 2026-09-15.\n\nAffected:\n\n- Exploit Intelligence\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat AI Inference Server\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel 4 for Quarkus 3\n- Red Hat build of Apache Camel for Spring Boot 4\n- Red Hat build of Apicurio Registry 3\n- Red Hat build of Debezium 3\n- Red Hat Build of Keycloak\n- Red Hat build of Quarkus\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 7\n- Red Hat Ceph Storage 8\n- Red Hat Ceph Storage 9\n- Red Hat Certificate System 10\n- Red Hat Certificate System 11\n- Red Hat Data Grid 8\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat Fuse 7\n- Red Hat JBoss Enterprise Application Platform 8\n- Red Hat JBoss Enterprise Application Platform Expansion Pack\n- Red Hat JBoss Web Server 7\n- Red Hat Lightspeed for Runtimes Operator\n- Red Hat Offline Knowledge Portal\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Dev Spaces\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n\nFixed:\n\n- Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server\n- Red Hat JBoss EAP 7.4 ELS for RHEL 8\n- Red Hat JBoss EAP 7.4 ELS for RHEL 9\n\nNo fix planned:\n\n- Exploit Intelligence\n- OpenShift Developer Tools and Services\n- OpenShift Serverless\n- Red Hat AI Inference Server\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel 4 for Quarkus 3\n- Red Hat build of Apache Camel for Spring Boot 4\n- Red Hat build of Apicurio Registry 3\n- Red Hat build of Debezium 3\n- Red Hat Build of Keycloak\n- Red Hat build of Quarkus\n- Red Hat Ceph Storage 6\n- Red Hat Ceph Storage 7\n- Red Hat Ceph Storage 8\n- Red Hat Ceph Storage 9\n- Red Hat Certificate System 10\n- Red Hat Certificate System 11\n- Red Hat Data Grid 8\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat Fuse 7\n- Red Hat JBoss Web Server 7\n- Red Hat Lightspeed for Runtimes Operator\n- Red Hat Offline Knowledge Portal\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Dev Spaces\n- Red Hat Satellite 6\n- Red Hat Single Sign-On 7\n- Red Hat JBoss Enterprise Application Platform 8\n- Red Hat JBoss Enterprise Application Platform Expansion Pack\n\nNot affected:\n\n- Red Hat Hardened Images\n\n## Remediation\n\nBefore applying the update, make sure all previously released errata relevant to\nyour system have been applied. Also, back up your existing installation,\nincluding all applications, configuration files, databases and database\nsettings. For details on how to apply this update, refer to:\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67604\n\n## Package advisory (CVE-2026-59889)\n\nAffected packages:\n\n- `com.fasterxml.jackson.core:jackson-databind >= 2.21.0, < 2.21.5`\n- `tools.jackson.core:jackson-databind >= 3.0.0, <= 3.1.4`\n- `com.fasterxml.jackson.core:jackson-databind >= 2.18.0, <= 2.18.8`\n- `com.fasterxml.jackson.core:jackson-databind >= 2.22.0, < 2.22.1`\n- `tools.jackson.core:jackson-databind >= 3.2.0, < 3.2.1`\n\nPatched in:\n\n- `com.fasterxml.jackson.core:jackson-databind 2.21.5`\n- `tools.jackson.core:jackson-databind 3.1.5`\n- `com.fasterxml.jackson.core:jackson-databind 2.18.9`\n- `com.fasterxml.jackson.core:jackson-databind 2.22.1`\n- `tools.jackson.core:jackson-databind 3.2.1`\n\nSource: https://github.com/advisories/GHSA-5gvw-p9qm-jgwh","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}