« Back to list

Cloudfoundry

Cloudfoundry UAA: vulnerabilities and CVEs

Cloudfoundry UAA has 6 published vulnerabilities, 5 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months5
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-59335High (8.7)0.53%—Aug 25, 2026
Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority…
CVE-2026-47840Critical (9.3)0.22%—Jul 9, 2026
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during…
CVE-2026-41005Critical (9)0.16%—Jun 11, 2026
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer…
CVE-2026-40965Critical (10)0.46%—Jun 1, 2026
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public…
CVE-2026-22734High (8.6)0.36%—Apr 17, 2026
Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a…
CVE-2025-22216Medium (5.4)0.19%—Jan 31, 2025
A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1078 Valid Accounts1
  3. T1078.001 Default Accounts1
  4. T1210 Exploitation of Remote Services1
  5. T1212 Exploitation for Credential Access1
  6. T1552.004 Private Keys1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Cloudfoundry