Bug 2500653 (CVE-2026-59889)

Summary: CVE-2026-59889 com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aakkiang, alinfoot, amctagga, anthomas, ant, anujha, aoconnor, aschwart, asoldano, asyoung, aszczucz, ataylor, avibelli, bbaranow, bbrownin, bgeorges, bmaxwell, bniver, boliveir, bstansbe, ccranfor, cescoffi, cfu, cmah, csutherl, dandread, dbruscin, dfreiber, dhanak, dkreling, dlofthou, drichtar, drosa, drow, dschmidt, dsimansk, dsoumis, dtrifiro, ebaron, edewata, ehelms, ehugonne, ewittman, flucifre, fmariani, fmongiar, gbenhaim, ggainey, gkimetto, gmalinko, gmeno, groman, gsmet, gtanzill, istudens, ivassile, iweiss, janstey, jburrell, jbuscemi, jclere, jhollowa, jlanda, jmagne, jmartisk, jnethert, jpasqual, jpechane, juwatts, jwon, kaycoth, kingland, kshier, kvanderr, lthon, manderse, mbenjamin, mcarlett, mdellweg, mfargett, mhackett, mhulan, mnovotny, mosmerov, mposolda, msvehla, nipatil, niyer, nmoumoul, nwallace, olubyans, osousa, pantinor, pberan, pcreech, pdelbell, pesilva, pgallagh, pjindal, plodge, pmackay, prichard, prisingh, probinso, rbryant, rchan, rguimara, rhel-process-autobot, rkubis, rmartinc, rmaucher, rruss, rstancel, rstepani, rsvoboda, sausingh, sbiarozk, sdawley, simaishi, skhandel, smallamp, snegrini, sostapov, ssilvert, stcannon, sthirugn, sthorger, szappis, taherrin, tcunning, teagle, thjenkin, tmalecek, tqvarnst, twaugh, vdosoudi, vereddy, vkumar, vmuzikar, watson-tool-maintainers, weaton, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to write data to a property annotated with both @JsonView and @JsonUnwrapped even when deserializing under a less-privileged view. This can lead to mass-assignment and privilege escalation, enabling an untrusted caller to modify sensitive data that should be restricted to privileged users.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-14 21:03:05 UTC
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.

Comment 2 Jon Orris 2026-09-15 14:41:20 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4.25

Via RHSA-2026:67603 https://access.redhat.com/errata/RHSA-2026:67603

Comment 3 Jon Orris 2026-09-15 14:44:39 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8
  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9

Via RHSA-2026:67604 https://access.redhat.com/errata/RHSA-2026:67604

Comment 4 Jon Orris 2026-09-22 12:57:02 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8

Via RHSA-2026:70228 https://access.redhat.com/errata/RHSA-2026:70228

Comment 5 Jon Orris 2026-09-22 12:59:27 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10

Via RHSA-2026:70230 https://access.redhat.com/errata/RHSA-2026:70230

Comment 6 Jon Orris 2026-09-22 13:01:36 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9

Via RHSA-2026:70229 https://access.redhat.com/errata/RHSA-2026:70229

Comment 7 Jon Orris 2026-09-22 15:36:35 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1

Via RHSA-2026:70277 https://access.redhat.com/errata/RHSA-2026:70277