CVE-2026-86512
A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.21%
- CWE
- CWE-284, CWE-266
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- java-json-tools json-patch
- java-json-tools json-patch
- java-json-tools json-patch
- java-json-tools json-patch
- java-json-tools json-patch
- java-json-tools json-patch
- java-json-tools json-patch
- java-json-tools json-patch
Weakness type
Related vulnerabilities
- CVE-2026-86774 — Snipe-IT before 8.7.0 Broken Access Control via AssetModelPolicy
- CVE-2026-19625 — IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities
- CVE-2026-75998 — ColdFusion | Improper Access Control (CWE-284)
- CVE-2026-86672 — ningzichun Student Management System Backup example.7z information disclosure
- CVE-2026-81963 — Windows Update Stack Elevation of Privilege Vulnerability
- CVE-2026-77487 — SQL Server Elevation of Privilege Vulnerability
- CVE-2026-73028 — SQL Server Elevation of Privilege Vulnerability
- CVE-2026-69282 — Microsoft Office SharePoint Remote Code Execution Vulnerability