Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-86512

CVE-2026-86512: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium6.3

    Medium [CVE-2026-86512] java-json-tools json-patch: Improper Access Control in Copy/Move Operations

    CVE-2026-86512Source published Source updated

    java-json-tools json-patch: Improper Access Control in Copy/Move Operations. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-281. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 1 more.

    Related products — impact not confirmed
    • Red Hat build of Apicurio Registry 3
    • Red Hat build of Debezium 3
    • Red Hat Build of Keycloak
    • Red Hat build of Quarkus

    1 more entries in the full advisory.

    Source-reported affected versions
    • 1.13
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • There is no official patch available for this vulnerability. Until a fix is released, administrators can implement the following mitigations to reduce the risk of access control bypass attacks: 1. Implement strict path validation before applying JSON Patch operations. Maintain an allowlist of permitted source and destination paths, and reject any patch operations that reference paths outside the allowlist. This prevents unauthorized copy/move operations on restricted data. 2. For applications using JSON Patch on user-modifiable data, implement an additional access control layer that validates whether the authenticated user has permission to read from the source path and write to the destination path before applying copy or move operations. 3. Avoid using JSON Patch for operations on security-sensitive data structures such as user permissions, roles, privileges, or access control lists. Use dedicated, validated APIs for these operations instead. 4. In multi-tenant environments, ensure tenant isolation is enforced at a layer above the JSON Patch processing, preventing cross-tenant path access even if the json-patch library allows it. 5. Apply the principle of least privilege to JSON document structures. Separate sensitive data into distinct documents or services that are not accessible via JSON Patch operations. 6. Monitor for suspicious JSON Patch operations, particularly copy and move operations that reference unusual paths or attempt to access administrative or system paths. 7. Where possible, restrict JSON Patch processing to authenticated and trusted sources only. Implement rate limiting and logging for all JSON Patch operations to detect potential exploitation attempts. 8. Consider migrating to alternative, actively maintained JSON manipulation libraries such as Jackson JSON or JSON-P (Java EE standard) that may have more robust access control implementations. Continue to monitor for updates from the json-patch project maintainers and apply patches when they become available.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery