---
id: CVE-2026-59889
title: >-
  com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege
  escalation via improper handling of @JsonUnwrapped properties (CVE…
summary: >-
  A flaw was found in jackson-databind. The
  UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling
  @JsonUnwrapped properties, replays buffered JSON without properly checking the
  active view. This allows an attacker to w…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
cwe:
  - CWE-915
  - CWE-863
vendor: Red Hat
product: Red Hat JBoss EAP 7.4 ELS for RHEL 8
affected:
  - exploit_intelligence
  - openshift_developer_tools_and_services
  - openshift_serverless
  - ai_inference_server
  - amq_broker 7
  - ansible_automation_platform 2
  - build_of_apache_camel_4_for_quarkus 3
  - build_of_apache_camel_for_spring_boot 4
  - build_of_apicurio_registry 3
  - build_of_debezium 3
  - build_of_keycloak
  - build_of_quarkus
  - ceph_storage 6
  - ceph_storage 7
  - ceph_storage 8
  - ceph_storage 9
  - certificate_system 10
  - certificate_system 11
  - data_grid 8
  - enterprise_linux 10
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
  - fuse 7
  - jboss_enterprise_application_platform 8
  - jboss_enterprise_application_platform_expansion_pack
  - jboss_web_server 7
  - lightspeed_for_runtimes_operator
  - offline_knowledge_portal
  - openshift_ai_rhoai
  - openshift_dev_spaces
  - satellite 6
  - single_sign_on 7
  - jboss_eap_7_4_els_for_rhel_7_server
  - jboss_eap_7_4_els_for_rhel 8
  - jboss_eap_7_4_els_for_rhel 9
patched:
  - jboss_eap_7_4_els_for_rhel_7_server
  - jboss_eap_7_4_els_for_rhel 8
  - jboss_eap_7_4_els_for_rhel 9
published: '2026-07-14'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T15:04:51+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59889.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59889.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-59889'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2500653'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-59889'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59889'
  - url: >-
      https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b
  - url: 'https://github.com/FasterXML/jackson-databind/issues/6060'
  - url: 'https://github.com/FasterXML/jackson-databind/pull/6056'
  - url: >-
      https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5gvw-p9qm-jgwh
  - url: 'https://access.redhat.com/errata/RHSA-2026:67604'
  - url: 'https://github.com/advisories/GHSA-5gvw-p9qm-jgwh'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - maven
epss: 0.00346
epssPercentile: 0.28248
aliases:
  - GHSA-5gvw-p9qm-jgwh
ecosystem: maven
ingestedAt: '2026-07-21T22:55:08.724Z'
---

## Overview

A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to write data to a property annotated with both @JsonView and @JsonUnwrapped even when deserializing under a less-privileged view. This can lead to mass-assignment and privilege escalation, enabling an untrusted caller to modify sensitive data that should be restricted to privileged users.

## Vendor advisories

- **RHSA-2026:67604** · Red Hat · fixed in: Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server, Red Hat JBoss EAP 7.4 ELS for RHEL 8, Red Hat JBoss EAP 7.4 ELS for RHEL 9 · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67604)
- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat AI Inference Server, Red Hat AMQ Broker 7, Red Hat Ansible Automation Platform 2, … · no fix planned: Exploit Intelligence, OpenShift Developer Tools and Services, OpenShift Serverless, Red Hat AI Inference Server, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59889.json)

**com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties** — rated Moderate by Red Hat. Released 2026-07-14, updated 2026-09-15.

Affected:

- Exploit Intelligence
- OpenShift Developer Tools and Services
- OpenShift Serverless
- Red Hat AI Inference Server
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel 4 for Quarkus 3
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat build of Apicurio Registry 3
- Red Hat build of Debezium 3
- Red Hat Build of Keycloak
- Red Hat build of Quarkus
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Certificate System 10
- Red Hat Certificate System 11
- Red Hat Data Grid 8
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Fuse 7
- Red Hat JBoss Enterprise Application Platform 8
- Red Hat JBoss Enterprise Application Platform Expansion Pack
- Red Hat JBoss Web Server 7
- Red Hat Lightspeed for Runtimes Operator
- Red Hat Offline Knowledge Portal
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Dev Spaces
- Red Hat Satellite 6
- Red Hat Single Sign-On 7

Fixed:

- Red Hat JBoss EAP 7.4 ELS for RHEL 7 Server
- Red Hat JBoss EAP 7.4 ELS for RHEL 8
- Red Hat JBoss EAP 7.4 ELS for RHEL 9

No fix planned:

- Exploit Intelligence
- OpenShift Developer Tools and Services
- OpenShift Serverless
- Red Hat AI Inference Server
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel 4 for Quarkus 3
- Red Hat build of Apache Camel for Spring Boot 4
- Red Hat build of Apicurio Registry 3
- Red Hat build of Debezium 3
- Red Hat Build of Keycloak
- Red Hat build of Quarkus
- Red Hat Ceph Storage 6
- Red Hat Ceph Storage 7
- Red Hat Ceph Storage 8
- Red Hat Ceph Storage 9
- Red Hat Certificate System 10
- Red Hat Certificate System 11
- Red Hat Data Grid 8
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Fuse 7
- Red Hat JBoss Web Server 7
- Red Hat Lightspeed for Runtimes Operator
- Red Hat Offline Knowledge Portal
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Dev Spaces
- Red Hat Satellite 6
- Red Hat Single Sign-On 7
- Red Hat JBoss Enterprise Application Platform 8
- Red Hat JBoss Enterprise Application Platform Expansion Pack

Not affected:

- Red Hat Hardened Images

## Remediation

Before applying the update, make sure all previously released errata relevant to
your system have been applied. Also, back up your existing installation,
including all applications, configuration files, databases and database
settings. For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67604

## Package advisory (CVE-2026-59889)

Affected packages:

- `com.fasterxml.jackson.core:jackson-databind >= 2.21.0, < 2.21.5`
- `tools.jackson.core:jackson-databind >= 3.0.0, <= 3.1.4`
- `com.fasterxml.jackson.core:jackson-databind >= 2.18.0, <= 2.18.8`
- `com.fasterxml.jackson.core:jackson-databind >= 2.22.0, < 2.22.1`
- `tools.jackson.core:jackson-databind >= 3.2.0, < 3.2.1`

Patched in:

- `com.fasterxml.jackson.core:jackson-databind 2.21.5`
- `tools.jackson.core:jackson-databind 3.1.5`
- `com.fasterxml.jackson.core:jackson-databind 2.18.9`
- `com.fasterxml.jackson.core:jackson-databind 2.22.1`
- `tools.jackson.core:jackson-databind 3.2.1`

Source: https://github.com/advisories/GHSA-5gvw-p9qm-jgwh
