Bug 2500653 (CVE-2026-59889) - CVE-2026-59889 com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties
Summary: CVE-2026-59889 com.fasterxml.jackson.core/jackson-databind: Jackson-databind:...
Keywords:
Status: NEW
Alias: CVE-2026-59889
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-14 21:03 UTC by OSIDB Bzimport
Modified: 2026-09-22 15:36 UTC (History)
143 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:67603 0 None None None 2026-09-15 14:41:28 UTC
Red Hat Product Errata RHSA-2026:67604 0 None None None 2026-09-15 14:44:46 UTC
Red Hat Product Errata RHSA-2026:70228 0 None None None 2026-09-22 12:57:10 UTC
Red Hat Product Errata RHSA-2026:70229 0 None None None 2026-09-22 13:01:43 UTC
Red Hat Product Errata RHSA-2026:70230 0 None None None 2026-09-22 12:59:33 UTC
Red Hat Product Errata RHSA-2026:70277 0 None None None 2026-09-22 15:36:43 UTC

Description OSIDB Bzimport 2026-07-14 21:03:05 UTC
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.18.0 until 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1, UnwrappedPropertyHandler.processUnwrapped() replays buffered JSON for a @JsonUnwrapped property and calls prop.deserializeAndSet() without a prop.visibleInView(ctxt.getActiveView()) guard, allowing a property annotated with both @JsonView and @JsonUnwrapped to be written from attacker JSON under a less-privileged active view. This issue is fixed in versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1.

Comment 2 Jon Orris 2026-09-15 14:41:20 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4.25

Via RHSA-2026:67603 https://access.redhat.com/errata/RHSA-2026:67603

Comment 3 Jon Orris 2026-09-15 14:44:39 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8
  Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9

Via RHSA-2026:67604 https://access.redhat.com/errata/RHSA-2026:67604

Comment 4 Jon Orris 2026-09-22 12:57:02 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8

Via RHSA-2026:70228 https://access.redhat.com/errata/RHSA-2026:70228

Comment 5 Jon Orris 2026-09-22 12:59:27 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10

Via RHSA-2026:70230 https://access.redhat.com/errata/RHSA-2026:70230

Comment 6 Jon Orris 2026-09-22 13:01:36 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9

Via RHSA-2026:70229 https://access.redhat.com/errata/RHSA-2026:70229

Comment 7 Jon Orris 2026-09-22 15:36:35 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 8.1

Via RHSA-2026:70277 https://access.redhat.com/errata/RHSA-2026:70277


Note You need to log in before you can comment on or make changes to this bug.