Metrics
Affected Vendors & Products
Wed, 09 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control | |
| First Time appeared |
Java-json-tools
Java-json-tools json-patch |
|
| Weaknesses | CWE-266 CWE-284 |
|
| CPEs | cpe:2.3:a:java-json-tools:json-patch:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Java-json-tools
Java-json-tools json-patch |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-09-08T02:15:13.531Z
Updated: 2026-09-09T15:23:11.907Z
Reserved: 2026-09-07T19:06:36.411Z
Link: CVE-2026-86512
Updated: 2026-09-09T15:23:07.390Z
Status : Deferred
Published: 2026-09-08T03:17:19.433
Modified: 2026-09-09T16:17:14.410
Link: CVE-2026-86512
No data.