Red Hat Updates cjose for CVE-2026-53938 Across RHEL 9 SAP Solutions Branches

P1 — VALIDATE AND UPDATEHigh · 8.2 (official CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat published RHSA-2026:73017 and RHSA-2026:73018 for cjose on entitled RHEL 9.2 and 9.4 SAP Solutions E4S streams. Inventory only entitled systems in the listed branches, apply cjose-0:0.6.1-13.el9_2.1.src / cjose-0:0.6.1-16.el9_4.1.src, validate JOSE token-processing, authentication, and SAP application workflows, and retain entitlement, package, and change evidence.

Confirm Scope And Apply The Supported Fix

What to do now: Identify entitled systems in the exact advisory branches, confirm the installed source package, apply cjose-0:0.6.1-13.el9_2.1.src / cjose-0:0.6.1-16.el9_4.1.src, validate JOSE token-processing, authentication, and SAP application workflows, and preserve entitlement, package-manager, service, and test evidence.

Open the authoritative advisory

Last verified: 2026-09-29 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopecjose on entitled RHEL 9.2 and 9.4 SAP Solutions E4S streams
AdvisoryRHSA-2026:73017 / RHSA-2026:73018
CVECVE-2026-53938
Authoritative release date2026-09-29 07:08:01 UTC
Authority revision date2026-09-29 10:15:46 UTC
Affected versionsThe RHEL 9.2 and 9.4 AppStream E4S branches identified by RHSA-2026:73017 and RHSA-2026:73018 before their advisory-listed fixed builds.
Fixed versioncjose-0:0.6.1-13.el9_2.1.src / cjose-0:0.6.1-16.el9_4.1.src
CVSS base score8.2 (official CVSS v3.1)
CVSS severityHigh
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

Red Hat corrected CVE-2026-53938 in branch-specific cjose packages for supported RHEL SAP Solutions E4S streams.

What To Validate Now

  1. Inventory. Locate entitled systems using cjose on entitled RHEL 9.2 and 9.4 SAP Solutions E4S streams; record the RHEL minor stream, repository entitlement, source package, architecture, owner, and dependent applications.
  2. Establish applicability. Match each system to RHSA-2026:73017 and RHSA-2026:73018. The RHEL 9.2 and 9.4 AppStream E4S branches identified by RHSA-2026:73017 and RHSA-2026:73018 before their advisory-listed fixed builds. Do not generalize this branch-specific fix to other RHEL streams.
  3. Remediate. Apply cjose-0:0.6.1-13.el9_2.1.src / cjose-0:0.6.1-16.el9_4.1.src through the matching entitled Red Hat repository and normal change control; Red Hat states that no qualifying workaround is available.
  4. Validate. Confirm the resulting package and repository branch, exercise representative JOSE token-processing, authentication, and SAP application workflows, monitor for regressions, and document exceptions or rollback.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

These are branch-specific extended-support fixes. Confirm entitlement and repository configuration before deployment, preserve configuration and rollback options, and do not treat the CVSS score as evidence of exploitation.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.