CVE-2026-59889
Medium (6.5)
A vulnerability in jackson-databind allows the @JsonView annotation to be bypassed for properties annotated with @JsonUnwrapped in container types during deserialization, potentially exposing data that should be restricted based on the active view. An authenticated attacker may be able to access fields marked as view-restricted in affected versions of the library.
- Reserved
- Jul 8, 2026
- Published
- Jul 14, 2026
- Modified
- Jul 22, 2026
CVSS Assessment
Source: CVE project
Version 3.1
Current
Medium (6.5)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
| Version | Status | Supplier | |||
|---|---|---|---|---|---|
| wire-transfer-service-3bb44c867b88300b898034bd4b06d0f08185cbbd | 3bb44c867b88300b898034bd4b06d0f08185cbbd |
Affected | 145 | Lightwell | Aug 17, 2026 |
1 - 1 of 1
| ID | Title | Type | Revision | Vulnerabilities |
|---|---|---|---|---|
| CVE-2026-59889 | jackson-databind: @JsonView annotation bypassed for @JsonUnwrapped container properties | cve | Jul 22, 2026 | 1 |
| GHSA-2m7j-p94x-kq8r | osv | Jul 14, 2026 | 1 |
1 - 2 of 2