• Recent
    • Tags
    • Popular
    • Register
    • Login

    Please Note This forum exists for community support for the Mango product family and the Radix IoT Platform. Although Radix IoT employees participate in this forum from time to time, there is no guarantee of a response to anything posted here, nor can Radix IoT, LLC guarantee the accuracy of any information expressed or conveyed. Specific project questions from customers with active support contracts are asked to send requests to support@radixiot.com.

    Radix IoT Website Mango Documentation Radix IoT LinkedIn

    Security Advisory: Upgrade to Mango 5.6.12 or 5.7.5

    Scheduled Pinned Locked Moved Announcements
    1 Posts 1 Posters 11 Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • joeamiragliaJ Offline
      joeamiraglia
      last edited by

      Mango 5.6.11 / 5.6.12 (Aug 25 and Sep 1, 2026) and Mango 5.7.5 (Aug 25, 2026) contain fixes for several security issues. If you're running an earlier version on either line, we recommend upgrading as soon as your maintenance window allows.

      Affected versions: All 5.6.x releases prior to 5.6.11, and all 5.7.x releases prior to 5.7.5.

      Vulnerabilities fixed:

      • Privilege escalation (core). Any user with a script engine permission could evaluate scripts with arbitrary roles, including superadmin.
      • Path traversal (core). File store operations did not reject paths that traverse a symbolic link pointing outside the file store. A symlink placed inside a file store could be used to escape it.
      • Modbus serial permission bypass (modbus-ds). The Modbus serial locator, serial write, and scan tools did not require the data source permission, unlike their IP equivalents. Any authenticated user could write to serial Modbus devices or trigger scans.
      • BACnet denial of service (bacnet-ds). A malformed or malicious BACnet message could trigger an infinite loop. Fixed by upgrading BACnet4J to 6.1.1.
      • Dependency CVEs. A broad set of third-party libraries were updated to patched versions, including Spring Framework, Spring Security, Jetty, Netty, Jackson, PostgreSQL JDBC, jOOQ, log4j, BouncyCastle, and Apache HttpComponents. lz4-java was upgraded to 1.11.1, fixing CVE-2026-59949 (a native-code JVM crash), and Spring LDAP was upgraded to address CVE-2026-41720.

      Breaking changes to review before upgrading:

      • Evaluating a script while requesting roles the caller does not hold now fails with a permission error instead of being silently allowed. If any of your scripts request roles beyond what the calling user holds, update them before upgrading.
      • (5.7.5 only) The REST API now ignores the read-only id property in request bodies. Object identity comes from the URL path or xid instead.
      • (5.6.11 only) BACnet REST serialization of CharacterString values now represents the character encoding as an object rather than a byte.

      Also in 5.6.12: a fix for OAuth 2.0 / OpenID Connect logins resetting a user's roles to user when oauth2.client.registration.{registrationId}.userMapping.roles.sync is set to false. Roles assigned by an administrator in Mango are now preserved across logins.

      As with any upgrade, back up your database and configuration first and test in a non-production environment before rolling out to production. Full details are in the 5.6.x and 5.7.x release notes.

      1 Reply Last reply Reply Quote 0

      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

      With your input, this post could be even better 💗

      Register Login
      • First post
        Last post