<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Security Advisory: Upgrade to Mango 5.6.12 or 5.7.5]]></title><description><![CDATA[<p dir="auto">Mango 5.6.11 / 5.6.12 (Aug 25 and Sep 1, 2026) and Mango 5.7.5 (Aug 25, 2026) contain fixes for several security issues. If you're running an earlier version on either line, we recommend upgrading as soon as your maintenance window allows.</p>
<p dir="auto"><strong>Affected versions:</strong> All 5.6.x releases prior to 5.6.11, and all 5.7.x releases prior to 5.7.5.</p>
<p dir="auto"><strong>Vulnerabilities fixed:</strong></p>
<ul>
<li><strong>Privilege escalation (core).</strong> Any user with a script engine permission could evaluate scripts with arbitrary roles, including superadmin.</li>
<li><strong>Path traversal (core).</strong> File store operations did not reject paths that traverse a symbolic link pointing outside the file store. A symlink placed inside a file store could be used to escape it.</li>
<li><strong>Modbus serial permission bypass (modbus-ds).</strong> The Modbus serial locator, serial write, and scan tools did not require the data source permission, unlike their IP equivalents. Any authenticated user could write to serial Modbus devices or trigger scans.</li>
<li><strong>BACnet denial of service (bacnet-ds).</strong> A malformed or malicious BACnet message could trigger an infinite loop. Fixed by upgrading BACnet4J to 6.1.1.</li>
<li><strong>Dependency CVEs.</strong> A broad set of third-party libraries were updated to patched versions, including Spring Framework, Spring Security, Jetty, Netty, Jackson, PostgreSQL JDBC, jOOQ, log4j, BouncyCastle, and Apache HttpComponents. lz4-java was upgraded to 1.11.1, fixing CVE-2026-59949 (a native-code JVM crash), and Spring LDAP was upgraded to address CVE-2026-41720.</li>
</ul>
<p dir="auto"><strong>Breaking changes to review before upgrading:</strong></p>
<ul>
<li>Evaluating a script while requesting roles the caller does not hold now fails with a permission error instead of being silently allowed. If any of your scripts request roles beyond what the calling user holds, update them before upgrading.</li>
<li>(5.7.5 only) The REST API now ignores the read-only id property in request bodies. Object identity comes from the URL path or xid instead.</li>
<li>(5.6.11 only) BACnet REST serialization of CharacterString values now represents the character encoding as an object rather than a byte.</li>
</ul>
<p dir="auto"><strong>Also in 5.6.12:</strong> a fix for OAuth 2.0 / OpenID Connect logins resetting a user's roles to user when oauth2.client.registration.{registrationId}.userMapping.roles.sync is set to false. Roles assigned by an administrator in Mango are now preserved across logins.</p>
<p dir="auto">As with any upgrade, back up your database and configuration first and test in a non-production environment before rolling out to production. Full details are in the <a href="https://docs.radixiot.com/docs/release-notes/5.6.x/" rel="nofollow ugc">5.6.x</a> and <a href="https://docs.radixiot.com/docs/release-notes/5.7.x/" rel="nofollow ugc">5.7.x</a> release notes.</p>
]]></description><link>https://forum.mango-os.com/topic/6189/security-advisory-upgrade-to-mango-5.6.12-or-5.7.5</link><generator>RSS for Node</generator><lastBuildDate>Thu, 03 Sep 2026 04:17:20 GMT</lastBuildDate><atom:link href="https://forum.mango-os.com/topic/6189.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 02 Sep 2026 13:15:46 GMT</pubDate><ttl>60</ttl></channel></rss>