CVE-2026-55772: Cedar-Policy Cedar-Java

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling could allow Record-to-Entity type confusion across the Java-Rust FFI boundary. CedarJava sends authorization requests to the Rust cedar-policy evaluator as JSON. The JSON protocol reserves magic single-key object shapes (__entity and __extn) for entity references and extension values. When serializing a CedarMap, there is no validation preventing these reserved keys from being used. If an integrating service builds a CedarMap from caller-supplied key/value data (such as request headers, user-defined metadata, or resource tags), an actor who controls those keys could cause the Rust evaluator to interpret a record as an entity reference. This issue requires the integrating service to build a CedarMap where the an actor controls the keys, and a policy must reference that value in a when/unless clause. This vulnerability has been fixed in versions 2.3.6, 3.4.1, and 4.9.

Affected products

  • Cedar-Policy Cedar-Java: before 2.3.6 (fixed in 2.3.6); from 3.1.2, before 3.4.1 (fixed in 3.4.1); from 4.0.0, before 4.9.0 (fixed in 4.9.0)

Published 2026-07-13. Last modified 2026-07-21.