Improperly Controlled Modification of Dynamically-Determined Object Attributes in jackson-databind - CVE-2026-59888
Published: July 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify dynamically determined object attributes.
The vulnerability exists due to improper control of dynamically determined object attributes in jackson-databind record deserialization when applying a PropertyNamingStrategy to `@JsonIgnore`-annotated Record properties. A remote attacker can supply a specially crafted JSON key to modify dynamically determined object attributes.
This issue affects Java Records during deserialization when a naming strategy is used and `@JsonIgnore` is relied on to prevent a component from being set from input.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
Development Tools Module
Basesystem Module
IBM Common Licensing
IBM SPSS Collaboration and Deployment Services
CICS Transaction Gateway Desktop Edition
Keycloak
jackson-dataformat-cbor
jackson-annotations
jackson-core
jackson-databind
EntireX
How to mitigate CVE-2026-59888
IBM Common Licensing - update to 9.1
Keycloak - update to 26.7.2
jackson-dataformat-cbor - update to 2.18.9-150200.3.24.1
jackson-annotations - update to 2.18.9-150200.3.25.1
jackson-core - update to 2.18.9-150200.3.25.1
jackson-databind - update to 2.18.9-150200.3.33.1
IBM SPSS Collaboration and Deployment Services - addressed in versions 8.4.0.0 IF005, 8.5.0.0 IF005, 8.6.0.0 IF005
EntireX - update to 12.1.0.0003-0779
External References
Related Security Bulletins
- Multiple vulnerabilities in jackson-databind
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition
- SUSE update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in IBM EntireX
- Multiple vulnerabilities in IBM Common Licensing
- Multiple vulnerabilities in Keycloak
- Multiple vulnerabilities in Keycloak