CVE-2026-59889Medium· 6.5▾ SunlitA flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to w…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.4%
Last analysed / modified upstream
A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to write data to a property annotated with both @JsonView and @JsonUnwrapped even when deserializing under a less-privileged view. This can lead to mass-assignment and privilege escalation, enabling an untrusted caller to modify sensitive data that should be restricted to privileged users.
com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties — rated Moderate by Red Hat. Released 2026-07-14, updated 2026-09-15.
Affected:
Fixed:
No fix planned:
Not affected:
Before applying the update, make sure all previously released errata relevant to your system have been applied. Also, back up your existing installation, including all applications, configuration files, databases and database settings. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67604
Affected packages:
com.fasterxml.jackson.core:jackson-databind >= 2.21.0, < 2.21.5tools.jackson.core:jackson-databind >= 3.0.0, <= 3.1.4com.fasterxml.jackson.core:jackson-databind >= 2.18.0, <= 2.18.8com.fasterxml.jackson.core:jackson-databind >= 2.22.0, < 2.22.1tools.jackson.core:jackson-databind >= 3.2.0, < 3.2.1Patched in:
com.fasterxml.jackson.core:jackson-databind 2.21.5tools.jackson.core:jackson-databind 3.1.5com.fasterxml.jackson.core:jackson-databind 2.18.9com.fasterxml.jackson.core:jackson-databind 2.22.1tools.jackson.core:jackson-databind 3.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54515Medium· 5.3jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified (CVE-2026-54515)
CVE-2026-50193High· 7.5jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193)
CVE-2026-54512High· 8.1jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512)
CVE-2026-80110High· 8.1A flaw was found in pki-core
CVE-2026-92904Medium· 4.3A flaw was found in the foreman_remote_execution plugin's template invocations controller
CVE-2026-92893Medium· 4.3A flaw was found in the foreman_ansible plugin's Ansible inventory API