CVE-2026-54517: jackson-databind: @JsonView bypass for setterless creator properties
Summary In BeanDeserializer.deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch performed no prop.visibleInView(activeView) check. A change making SetterlessProperty.isMerging() return true routed setterless Collection/Map properties through this unguarded path, so a setterless collection annotated with a restricted @JsonView is populated from attacker JSON even when the active view excludes it.
Impact View-restricted (e.g. admin-only) setterless collection/map properties can be written from untrusted JSON despite @JsonView gating — an access-control / mass-assignment bypass. No RCE or DoS.
Affected / Patched (verified via git tag --contains) - 2.21 line: >= 2.21.0, < 2.21.4 -> fixed in 2.21.4 (backport 94c5d21, #5970) - 3.x line: >= 3.0.0, < 3.1.4 -> fixed in 3.1.4 (#5969, 5bf23ed)
Severity / CWE Maintainer: minor. Reporter: HIGH. CWE-863 (Incorrect Authorization); related CWE-1220.
Credits Omkhar Arasaratnam (@omkhar) - finder.
Other sources
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer.deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch performed no prop.visibleInView(activeView) check. A change making SetterlessProperty.isMerging() return true routed setterless Collection/Map properties through this unguarded path, so a setterless collection annotated with a restricted @JsonView is populated from attacker JSON even when the active view excludes it. This vulnerability is fixed in 2.21.4 and 3.1.4.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/tools.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 3.1.4 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 3.1.4 - Upgrade
Upgrade
maven/com.fasterxml.jackson.core:jackson-databindto a version that resolves this vulnerability.Fixed in 2.21.4 - Upgrade
Upgrade
jackson-databindto a version that resolves this vulnerability.Fixed in 2.21.4Patch 94c5d21 - Upgrade
Upgrade
jackson-databindto a version that resolves this vulnerability.Fixed in 3.1.4Patch #5969
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54517?
CVE-2026-54517 has a medium severity rating of 5.3.
How do I fix CVE-2026-54517?
To fix CVE-2026-54517, upgrade jackson-databind to version 2.21.5 or later, or 3.1.5 or later.
What are the affected versions of jackson-databind for CVE-2026-54517?
CVE-2026-54517 affects jackson-databind versions from 2.21.0 until 2.21.4 and version 3.1.4.
What is the main issue described in CVE-2026-54517?
The main issue in CVE-2026-54517 is a bypass of the @JsonView filter for setterless creator properties in jackson-databind.
What impact does CVE-2026-54517 have on applications?
CVE-2026-54517 can lead to unintended data exposure due to the improper application of view filters.