CVE-2026-59889

Medium (6.5)

A vulnerability in jackson-databind allows the @JsonView annotation to be bypassed for properties annotated with @JsonUnwrapped in container types during deserialization, potentially exposing data that should be restricted based on the active view. An authenticated attacker may be able to access fields marked as view-restricted in affected versions of the library.

Reserved
Jul 8, 2026
Published
Jul 14, 2026
Modified
Jul 22, 2026

CVSS Assessment

Source: CVE project

Version 3.1 Current
Medium (6.5)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
1 - 1 of 1
Version Status Supplier
wire-transfer-service-3bb44c867b88300b898034bd4b06d0f08185cbbd 3bb44c867b88300b898034bd4b06d0f08185cbbd Affected 145 Lightwell Aug 17, 2026
1 - 1 of 1
1 - 2 of 2
ID Title Type Revision Vulnerabilities
CVE-2026-59889 jackson-databind: @JsonView annotation bypassed for @JsonUnwrapped container properties cve Jul 22, 2026 1
GHSA-2m7j-p94x-kq8r osv Jul 14, 2026 1
1 - 2 of 2