CVE-2026-55772

HIGH

CedarJava - Record-to-Entity Type Confusion

Title source: manual
STIX 2.1

Description

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling could allow Record-to-Entity type confusion across the Java-Rust FFI boundary. CedarJava sends authorization requests to the Rust cedar-policy evaluator as JSON. The JSON protocol reserves magic single-key object shapes (__entity and __extn) for entity references and extension values. When serializing a CedarMap, there is no validation preventing these reserved keys from being used. If an integrating service builds a CedarMap from caller-supplied key/value data (such as request headers, user-defined metadata, or resource tags), an actor who controls those keys could cause the Rust evaluator to interpret a record as an entity reference. This issue requires the integrating service to build a CedarMap where the an actor controls the keys, and a policy must reference that value in a when/unless clause. This vulnerability has been fixed in versions 2.3.6, 3.4.1, and 4.9.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0027
EPSS Percentile 19.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-843
Status published
Products (6)
cedar-policy/cedar-java < 2.3.6
cedar-policy/cedar-java >= 3.1.2, < 3.4.1
cedar-policy/cedar-java >= 4.0.0, < 4.9.0
com.cedarpolicy/cedar-java 0 - 2.3.6Maven
com.cedarpolicy/cedar-java 3.1.2 - 3.4.1Maven
com.cedarpolicy/cedar-java 4.0.0 - 4.9.0Maven
Published Jul 13, 2026
Tracked Since Jul 14, 2026