CVE-2026-86512
Dashboard / Vulnerabilities / CVE-2026-86512
CVE-2026-86512
Summary: java-json-tools json-patch Copy Move Operations CopyOperation.java MoveOperation.apply access control
Details: A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to improper access controls. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86512.json, https://nvd.nist.gov/vuln/detail/CVE-2026-86512, https://vuldb.com/cve/CVE-2026-86512, https://vuldb.com/submit/908391, https://vuldb.com/vuln/399666, https://vuldb.com/vuln/399666/cti, https://github.com/java-json-tools/json-patch/, https://github.com/java-json-tools/json-patch/issues/170
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
