Improperly Controlled Modification of Dynamically-Determined Object Attributes in jackson-databind - CVE-2026-59888

 

Improperly Controlled Modification of Dynamically-Determined Object Attributes in jackson-databind - CVE-2026-59888

Published: July 22, 2026


Vulnerability identifier: #VU139152
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59888
CWE-ID: CWE-915
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify dynamically determined object attributes.

The vulnerability exists due to improper control of dynamically determined object attributes in jackson-databind record deserialization when applying a PropertyNamingStrategy to `@JsonIgnore`-annotated Record properties. A remote attacker can supply a specially crafted JSON key to modify dynamically determined object attributes.

This issue affects Java Records during deserialization when a naming strategy is used and `@JsonIgnore` is relied on to prevent a component from being set from input.


Affected software

jackson-databind
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Development Tools Module
Basesystem Module
IBM Common Licensing
IBM SPSS Collaboration and Deployment Services
CICS Transaction Gateway Desktop Edition
Keycloak
jackson-dataformat-cbor
jackson-annotations
jackson-core
jackson-databind
EntireX

How to mitigate CVE-2026-59888

Install security update from vendor's website.

jackson-databind - addressed in versions 2.18.8, 2.21.4, 3.1.4
IBM Common Licensing - update to 9.1
Keycloak - update to 26.7.2
jackson-dataformat-cbor - update to 2.18.9-150200.3.24.1
jackson-annotations - update to 2.18.9-150200.3.25.1
jackson-core - update to 2.18.9-150200.3.25.1
jackson-databind - update to 2.18.9-150200.3.33.1
IBM SPSS Collaboration and Deployment Services - addressed in versions 8.4.0.0 IF005, 8.5.0.0 IF005, 8.6.0.0 IF005
EntireX - update to 12.1.0.0003-0779

External References

Related Security Bulletins