RHSA-2026:48095HighCVSS 8.1

Red Hat Security Advisory: RHCS 10.8 bug fix and enhancement update

Published
July 29, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-54512 — jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass CVE-2026-54513 — jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution

🎯 Affected products33

  • Red Hat Certificate System 10.8 for RHEL 8
  • jss-0:5.9.1-2.module+el8pki+24483+db4528cf.src (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • jss-debuginfo-0:5.9.1-2.module+el8pki+24483+db4528cf.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • jss-debugsource-0:5.9.1-2.module+el8pki+24483+db4528cf.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • ldapjdk-0:5.6.0-3.module+el8pki+24228+5326976e.src (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • python3-redhat-pki-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-jss-0:5.9.1-2.module+el8pki+24483+db4528cf.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-jss-debuginfo-0:5.9.1-2.module+el8pki+24483+db4528cf.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-jss-javadoc-0:5.9.1-2.module+el8pki+24483+db4528cf.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-jss-tomcat-0:5.9.1-2.module+el8pki+24483+db4528cf.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-jss-tools-0:5.9.1-2.module+el8pki+24483+db4528cf.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-jss-tools-debuginfo-0:5.9.1-2.module+el8pki+24483+db4528cf.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-ldapjdk-0:5.6.0-3.module+el8pki+24228+5326976e.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-ldapjdk-javadoc-0:5.6.0-3.module+el8pki+24228+5326976e.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-0:11.9.2-4.module+el8pki+24565+7517ad63.src (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-0:11.9.2-4.module+el8pki+24565+7517ad63.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-acme-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-base-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-ca-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-console-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-console-theme-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-debugsource-0:11.9.2-4.module+el8pki+24565+7517ad63.x86_64 (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-est-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-java-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-javadoc-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-kra-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-ocsp-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-server-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-theme-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • redhat-pki-tks-0:11.9.2-4.module+el8pki+24565+7517ad63.noarch (redhat-pki:10) as a component of Red Hat Certificate System 10.8 for RHEL 8
  • +3 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Upgrade to version 2.18.8, 2.21.4, or 3.1.4 or later to address this vulnerability. If upgrading is not immediately possible, remove BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() from the application’s ObjectMapper configuration to eliminate the affected deserialization path. Rebuild and restart the application to apply the configuration change. As an additional mitigation, disable polymorphic deserialization of untrusted data where possible by avoiding or removing default typing features such as activateDefaultTyping() or enableDefaultTyping(). When polymorphic deserialization is required, restrict allowed subtypes using a strict whitelist of trusted application packages and avoid broad or permissive type validation rules.

🔗 References (3)