CVE-2026-54515
Medium (5.3)
A vulnerability in jackson-databind allows case-insensitive deserialization to bypass per-property @JsonIgnoreProperties annotations, potentially exposing sensitive fields during object deserialization. An unauthenticated remote attacker may be able to read protected fields in deserialized objects by exploiting case-insensitive property matching in affected versions of the library.
- Reserved
- Jun 12, 2026
- Published
- Jun 23, 2026
- Modified
- Jul 1, 2026
CVSS Assessment
Source: CVE project
Version 3.1
Current
Medium (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
| Version | Status | Supplier | |||
|---|---|---|---|---|---|
| wire-transfer-service-3bb44c867b88300b898034bd4b06d0f08185cbbd | 3bb44c867b88300b898034bd4b06d0f08185cbbd |
Affected | 145 | Lightwell | Aug 17, 2026 |
| ach-processor-9c33fbf37ab5e2e56921fec0e6df6df5c6fb6b57 | 9c33fbf37ab5e2e56921fec0e6df6df5c6fb6b57 |
Affected | 118 | Lightwell | Aug 17, 2026 |
| benefits-mgmt-app-9b416d7055d8de529f2255ff2b1db1ca22bc5781 | 9b416d7055d8de529f2255ff2b1db1ca22bc5781 |
Affected | 92 | Lightwell | Aug 17, 2026 |
1 - 3 of 3
| ID | Title | Type | Revision | Vulnerabilities |
|---|---|---|---|---|
| CVE-2026-54515 | jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties | cve | Jul 1, 2026 | 1 |
| GHSA-8m5h-ct42-w834 | osv | Jun 23, 2026 | 1 |
1 - 2 of 2