CVE Explorer
CVE-2026-55773
CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling could allow Cedar-expression injection via unescaped toCedarExpr(). The toCedarExpr() method on Cedar Value types does not escape special characters (" or \) when converting values to Cedar source code. If an integrator uses toCedarExpr() to build policy text at runtime from u
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cedar-java","vendor":"cedar-policy","versions":[{"status":"affected","version":"< 2.3.6"},{"status":"affected","version":">= 3.1.2, < 3.4.1"},{"status":"affected","version":">= 4.0.0, < 4.9.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:268ff3e461688e556c01b05f06f3a590f4693d966c4321a2c0c2a8d7b7ed0ad9 · sha256:66cb97f0d3284b63… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:268ff3e461688e556c01b05f06f3a590f4693d966c4321a2c0c2a8d7b7ed0ad9 · sha256:66cb97f0d3284b63… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-94","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:268ff3e461688e556c01b05f06f3a590f4693d966c4321a2c0c2a8d7b7ed0ad9 · sha256:66cb97f0d3284b63… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/cedar-policy/cedar-java/security/advisories/GHSA-qmch-v2q9-wg4p","tags":["x_refsource_CONFIRM"],"url":"https://github.com/cedar-policy/cedar-java/security/advisories/GHSA-qmch-v2q9-wg4p"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:268ff3e461688e556c01b05f06f3a590f4693d966c4321a2c0c2a8d7b7ed0ad9 · sha256:66cb97f0d3284b63… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.