CVE-2026-55771
HIGHCedarJava has policy injection, type confusion, and incorrect equality comparison vulnerabilities
Title source: cnaDescription
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals() has inverted null/self branches which could lead to incorrect equality comparisons. The EntityIdentifier.equals() method has inverted logic for null and self-reference checks, returning true for null comparisons and false for self-comparisons. This does not affect Cedar authorization decisions (computed in Rust from JSON), but could affect integrators who perform their own equality checks on entity identifiers. This issue has been fixed in version 4.9.0.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/cedar-policy/cedar-java/security/advisories/GHSA-4r9r-4425-74p7
Scores
CVSS v3
8.8
EPSS
0.0034
EPSS Percentile
27.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-697
CWE-843
CWE-94
Status
published
Products (4)
cedar-policy/cedar-java
< 4.9.0
com.cedarpolicy/cedar-java
0 - 2.3.6Maven
com.cedarpolicy/cedar-java
3.1.2 - 3.4.1Maven
com.cedarpolicy/cedar-java
4.0.0 - 4.9.0Maven
Published
Jul 13, 2026
Tracked Since
Jul 14, 2026