---
id: CVE-2026-86512
title: A vulnerability was identified in java-json-tools json-patch up to 1.13
summary: >-
  A vulnerability was identified in java-json-tools json-patch up to 1.13. This
  affects the function CopyOperation.apply/MoveOperation.apply of the file
  src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component
  Copy Move O…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-266
  - CWE-284
  - CWE-281
vendor: java-json-tools
product: json-patch
affected:
  - json-patch 1.0
  - json-patch 1.1
  - json-patch 1.2
  - json-patch 1.3
  - json-patch 1.4
  - json-patch 1.5
  - json-patch 1.6
  - json-patch 1.7
  - json-patch 1.8
  - json-patch 1.9
  - json-patch 1.10
  - json-patch 1.11
  - json-patch 1.12
  - json-patch 1.13
published: '2026-09-08'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:17:14.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86512'
references:
  - url: 'https://github.com/java-json-tools/json-patch/'
    label: cna@vuldb.com
  - url: 'https://github.com/java-json-tools/json-patch/issues/170'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86512'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/908391'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399666'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399666/cti'
    label: cna@vuldb.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86512.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-86512'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2529672'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-86512'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86512'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T15:23:01.658568Z'
epss: 0.00366
epssPercentile: 0.27748
ingestedAt: '2026-09-08T15:33:26.982Z'
---

## Overview

A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat build of Apicurio Registry 3, Red Hat build of Debezium 3, Red Hat Build of Keycloak, Red Hat build of Quarkus, Red Hat Fuse 7 · no fix planned: Red Hat build of Apicurio Registry 3, Red Hat Fuse 7, Red Hat build of Debezium 3, Red Hat Build of Keycloak, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86512.json)
