No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Sep 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control | |
| First Time appeared |
Java-json-tools
Java-json-tools json-patch |
|
| Weaknesses | CWE-266 CWE-284 |
|
| CPEs | cpe:2.3:a:java-json-tools:json-patch:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Java-json-tools
Java-json-tools json-patch |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-08T02:15:13.531Z
Reserved: 2026-09-07T19:06:36.411Z
Link: CVE-2026-86512
No data.
Status : Received
Published: 2026-09-08T03:17:19.433
Modified: 2026-09-08T03:17:19.433
Link: CVE-2026-86512
No data.
OpenCVE Enrichment
Updated: 2026-09-08T05:30:09Z