Improperly Controlled Modification of Dynamically-Determined Object Attributes in jackson-databind - CVE-2026-54515

 

Improperly Controlled Modification of Dynamically-Determined Object Attributes in jackson-databind - CVE-2026-54515

Published: July 22, 2026


Vulnerability identifier: #VU139156
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54515
CWE-ID: CWE-915
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify otherwise ignored object attributes.

The vulnerability exists due to improper control of dynamically determined object attributes in BeanDeserializerBase.createContextual() when processing case-insensitive deserialization with per-property @JsonIgnoreProperties exclusions. A remote attacker can send crafted JSON input to modify otherwise ignored object attributes.

Only applications that enable case-insensitive property matching and rely on per-property @JsonIgnoreProperties to keep a field unwritable are vulnerable.


Affected software

jackson-databind
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
Development Tools Module
Fedora
Netezza Appliance
Db2 Bridge
CICS Transaction Gateway Desktop Edition
WebSphere Automation
IBM Sterling Connect:Direct Web Services
IBM Maximo Application Suite - Manage Component
IBM Common Licensing
Red Hat build of Quarkus
IBM SPSS Collaboration and Deployment Services
jackson-dataformat-cbor
jackson-core
jackson-annotations
jackson-databind
jackson-parent
jackson-modules-base
jackson-jaxrs-providers
jackson-bom
fasterxml-oss-parent
EntireX

How to mitigate CVE-2026-54515

Install security update from vendor's website.

jackson-databind - addressed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.4
Netezza Appliance - update to 1.0.2.0
Db2 Bridge - update to 1.1.5.1
WebSphere Automation - update to 1.13.0
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.20, 6.4.0.9
IBM Maximo Application Suite - Manage Component - addressed in versions 9.0.28, 9.1.20, 9.2.1
IBM Common Licensing - update to 9.1
jackson-dataformat-cbor - addressed in versions 2.18.8-150200.3.21.3, 2.18.9-150200.3.24.1
jackson-core - addressed in versions 2.18.8-150200.3.22.3, 2.18.9-150200.3.25.1
jackson-annotations - addressed in versions 2.18.8-150200.3.22.3, 2.18.9-150200.3.25.1
jackson-databind - addressed in versions 2.18.8-150200.3.28.2, 2.18.9-150200.3.33.1
jackson-parent - update to 2.21-1.fc45
jackson-modules-base - update to 2.21.5-1.fc45
jackson-jaxrs-providers - update to 2.21.5-1.fc45
jackson-databind - update to 2.21.5-1.fc45
jackson-core - update to 2.21.5-1.fc45
jackson-bom - update to 2.21.5-1.fc45
jackson-annotations - update to 2.21-6.fc45
Red Hat build of Quarkus - addressed in versions 3.27.4.SP2, 3.33.2.SP2
IBM SPSS Collaboration and Deployment Services - addressed in versions 8.4.0.0 IF005, 8.5.0.0 IF005, 8.6.0.0 IF005
EntireX - update to 12.1.0.0003-0779
fasterxml-oss-parent - update to 75-1.fc45

External References

Related Security Bulletins