nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-47840 CVE-2026-47840
HIGH
LDAP StartTLS unconditionally disables hostname verification
Record summary
CVE-2026-47840 has a selected CVSS score of 8.3 (high).
Description
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 9, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Cf-deploymentBrowse CloudFoundry Foundation / Cf-deploymentDefault status: unaffected | CVE List | Before 56.2.0 | affected |
Default status: unaffected | CVE List | Before 78.13.0 | affected |
References
2cloudfoundry.org
https://www.cloudfoundry.org/blog/cve-2026-47840-ldap-starttls-unconditionally-disables-hostname-verification