Incorrect authorization in jackson-databind - CVE-2026-59889

 

Incorrect authorization in jackson-databind - CVE-2026-59889

Published: July 22, 2026


Vulnerability identifier: #VU139151
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59889
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in UnwrappedPropertyHandler.processUnwrapped() when deserializing @JsonUnwrapped container properties under a less-privileged active view. A remote user can supply crafted JSON values for a property annotated with both @JsonView and @JsonUnwrapped to escalate privileges.

This affects the write-side authorization behavior of @JsonView during deserialization, including merge and builder-based deserialization paths.


Affected software

jackson-databind
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
Basesystem Module
IBM Common Licensing
Maximo Application Suite - IoT Component
CICS Transaction Gateway Desktop Edition
Keycloak
jackson-dataformat-cbor
jackson-annotations
jackson-core
jackson-databind
EntireX

How to mitigate CVE-2026-59889

Install security update from vendor's website.

jackson-databind - addressed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, 3.2.1
IBM Common Licensing - update to 9.1
Maximo Application Suite - IoT Component - addressed in versions 9.0.22, 9.1.13, 9.2.1
Keycloak - update to 26.7.2
jackson-dataformat-cbor - update to 2.18.9-150200.3.24.1
jackson-annotations - update to 2.18.9-150200.3.25.1
jackson-core - update to 2.18.9-150200.3.25.1
jackson-databind - update to 2.18.9-150200.3.33.1
EntireX - update to 12.1.0.0003-0779

External References

Related Security Bulletins