Incorrect authorization in jackson-databind - CVE-2026-59889
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in UnwrappedPropertyHandler.processUnwrapped() when deserializing @JsonUnwrapped container properties under a less-privileged active view. A remote user can supply crafted JSON values for a property annotated with both @JsonView and @JsonUnwrapped to escalate privileges.
This affects the write-side authorization behavior of @JsonView during deserialization, including merge and builder-based deserialization paths.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Development Tools Module
Basesystem Module
IBM Common Licensing
Maximo Application Suite - IoT Component
CICS Transaction Gateway Desktop Edition
Keycloak
jackson-dataformat-cbor
jackson-annotations
jackson-core
jackson-databind
EntireX
How to mitigate CVE-2026-59889
IBM Common Licensing - update to 9.1
Maximo Application Suite - IoT Component - addressed in versions 9.0.22, 9.1.13, 9.2.1
Keycloak - update to 26.7.2
jackson-dataformat-cbor - update to 2.18.9-150200.3.24.1
jackson-annotations - update to 2.18.9-150200.3.25.1
jackson-core - update to 2.18.9-150200.3.25.1
jackson-databind - update to 2.18.9-150200.3.33.1
EntireX - update to 12.1.0.0003-0779
External References
Related Security Bulletins
- Multiple vulnerabilities in jackson-databind
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition
- SUSE update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in IBM EntireX
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in Keycloak
- Multiple vulnerabilities in Keycloak