CloudFoundry Foundation Vulnerabilities and Affected Products
Vulnerabilities associated with UAA.
Products
Clear product- CF Deployment2 vulnerabilities
- UAA2 vulnerabilities
- BOSH1 vulnerability
- BOSH CLI tool1 vulnerability
- bosh-cli1 vulnerability
- Cf-deployment1 vulnerability
- Routing release1 vulnerability
- smb-volume-release1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-47840HIGH | LDAP StartTLS unconditionally disables hostname verificationA network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0. CWE-297Jul 9, 2026 | CVSS8.3v4.0 | EPSS0.132% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22723MEDIUM | UAA User Token Revocation logic errorInappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0. | CVSS6.5v3.1 | EPSS0.224% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |