« Volver al listado

CVE-2026-59335

Estado: Pendiente de análisisAlta (8.7)—

Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restriction that this authority does not grant access to the privileged uaa (system) identity zone, by referring to the zone identifier in a non-lowercase form (e.g. UAA) in the request path and body.

Leer descripción completaMostrar menos

The authorization layer performs a case-sensitive comparison against the system zone identifier, while the underlying MySQL persistence layer resolves identifiers case-insensitively under its default collation, so the request is authorized incorrectly and is then resolved against the real system zone record. This allows the attacker to overwrite the system zone's JWT signing key with attacker-controlled key material, forge JWTs claiming the admin client and administrator scopes, and fully compromise UAA and any Cloud Foundry deployment that trusts it. This issue only affects UAA deployments backed by MySQL using its default collation; PostgreSQL and HSQLDB backends are not affected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Atacante autenticado remoto (PR:H) explota inconsistencia case-sensitivity en MySQL para eludir autorización y comprometer la zona UAA (T1210). Logra forjar JWTs como admin (T1078.001), manipular cuentas privilegiadas (T1098.003) y modificar claves de firma (T1565.001).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-59335",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-59335",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-25T13:08:56.301972Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Cloud Foundry",
          "product": "UAA",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "78.16.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "78.16.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Cloud Foundry",
          "product": "cf-deployment",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "57.0.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "57.0.0",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-08-25T11:16:53.817",
  "references": [
    {
      "url": "https://www.cloudfoundry.org/blog/cve-2026-59335-uaa-case-insensitive-check-bypass/",
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vmware.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-178"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restriction that this authority does not grant access to the privileged uaa (system) identity zone, by referring to the zone identifier in a non-lowercase form (e.g. UAA) in the request path and body. The authorization layer performs a case-sensitive comparison against the system zone identifier, while the underlying MySQL persistence layer resolves identifiers case-insensitively under its default collation, so the request is authorized incorrectly and is then resolved against the real system zone record. This allows the attacker to overwrite the system zone's JWT signing key with attacker-controlled key material, forge JWTs claiming the admin client and administrator scopes, and fully compromise UAA and any Cloud Foundry deployment that trusts it. This issue only affects UAA deployments backed by MySQL using its default collation; PostgreSQL and HSQLDB backends are not affected."
    },
    {
      "lang": "es",
      "value": "Manejo inadecuado de la distinción entre mayúsculas y minúsculas (CWE-178) en la verificación de autorización de la zona de identidad en el Endpoint de Zona de Identidad en Cloud Foundry UAA permite a un atacante remoto autenticado que posee únicamente la autoridad zones.write eludir la restricción prevista de que esta autoridad no otorga acceso a la zona de identidad privilegiada uaa (del sistema), al referirse al identificador de la zona en una forma que no sea minúscula (p. ej., UAA) en la ruta y el cuerpo de la solicitud. La capa de autorización realiza una comparación que distingue entre mayúsculas y minúsculas contra el identificador de la zona del sistema, mientras que la capa de persistencia subyacente de MySQL resuelve los identificadores sin distinguir entre mayúsculas y minúsculas bajo su intercalación predeterminada, por lo que la solicitud se autoriza incorrectamente y luego se resuelve contra el registro real de la zona del sistema. Esto permite al atacante sobrescribir la clave de firma JWT de la zona del sistema con material de clave controlado por el atacante, forjar JWTs que reclaman el cliente admin y los alcances administrator, y comprometer completamente UAA y cualquier despliegue de Cloud Foundry que confíe en él. Este problema solo afecta a los despliegues de UAA respaldados por MySQL que utilizan su intercalación predeterminada; los backends de PostgreSQL y HSQLDB no se ven afectados."
    }
  ],
  "lastModified": "2026-09-28T23:10:00.143",
  "sourceIdentifier": "security@vmware.com"
}