CVE-2026-54515

Medium (5.3)

A vulnerability in jackson-databind allows case-insensitive deserialization to bypass per-property @JsonIgnoreProperties annotations, potentially exposing sensitive fields during object deserialization. An unauthenticated remote attacker may be able to read protected fields in deserialized objects by exploiting case-insensitive property matching in affected versions of the library.

Reserved
Jun 12, 2026
Published
Jun 23, 2026
Modified
Jul 1, 2026

CVSS Assessment

Source: CVE project

Version 3.1 Current
Medium (5.3)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
1 - 3 of 3
Version Status Supplier
wire-transfer-service-3bb44c867b88300b898034bd4b06d0f08185cbbd 3bb44c867b88300b898034bd4b06d0f08185cbbd Affected 145 Lightwell Aug 17, 2026
ach-processor-9c33fbf37ab5e2e56921fec0e6df6df5c6fb6b57 9c33fbf37ab5e2e56921fec0e6df6df5c6fb6b57 Affected 118 Lightwell Aug 17, 2026
benefits-mgmt-app-9b416d7055d8de529f2255ff2b1db1ca22bc5781 9b416d7055d8de529f2255ff2b1db1ca22bc5781 Affected 92 Lightwell Aug 17, 2026
1 - 3 of 3
1 - 2 of 2
ID Title Type Revision Vulnerabilities
CVE-2026-54515 jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties cve Jul 1, 2026 1
GHSA-8m5h-ct42-w834 osv Jun 23, 2026 1
1 - 2 of 2