Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-55772 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling could allow Record-to-Entity type confusion across the Java-Rust FFI boundary. CedarJava sends authorization requests to the Rust cedar-policy evaluator as JSON. The JSON protocol reserves magic single-key object shapes (__entity and __extn) for entity references and extension values. When serializing a CedarMap, there is no validation preventing these reserved keys from being used. If an integrating service builds a CedarMap from caller-supplied key/value data (such as request headers, user-defined metadata, or resource tags), an actor who controls those keys could cause the Rust evaluator to interpret a record as an entity reference. This issue requires the integrating service to build a CedarMap where the an actor controls the keys, and a policy must reference that value in a when/unless clause. This vulnerability has been fixed in versions 2.3.6, 3.4.1, and 4.9.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-843Access of Resource Using Incompatible Type ('Type Confusion')[email protected]

Affected Products

ProductVersions
CedarJava
< 4.9

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Upgrade: 2.3.6moderate effort
  • Upgrade: 3.4.1moderate effort
  • Upgrade: 4.9moderate effort
  • Workaround:low effort

    Enable schema-based request validation to catch type mismatches. Validate that user-controlled data does not contain reserved keys ('__entity' or '__extn') before building 'CedarMap' objects.

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-55772
NVD Published Date:
Jul 13, 2026
NVD Last Modified:
Jul 21, 2026
Source:
[email protected]
CVE-2026-55772 Details - Not Deferred