SB2026090116 - Remote code execution in FasterXML jackson-databind



SB2026090116 - Remote code execution in FasterXML jackson-databind

Published: September 1, 2026

Security Bulletin ID SB2026090116
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Deserialization of Untrusted Data (CVE-ID: CVE-2026-83557)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to instantiate an unintended object and disclose, modify, or affect data handling.

The vulnerability exists due to deserialization of untrusted data in DefaultBaseTypeLimitingValidator when processing polymorphic type identifiers for @JsonTypeInfo-annotated Comparable-typed values without a custom PolymorphicTypeValidator. A remote attacker can supply a crafted type identifier to instantiate an attacker-chosen Comparable implementation to disclose, modify, or affect data handling.

Only the default, unconfigured validator path reached through bare @JsonTypeInfo usage is affected; configurations using activateDefaultTyping() with an explicit restrictive PolymorphicTypeValidator are not affected.


Remediation

Install update from vendor's website.