Cloud Foundry Logo
blog single gear
Security Advisory

CVE-2026-47839 – Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin

High

CVSS score: 9.2 (Critical) CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS score: 9.0 Critical) (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) 

Vendor

CloudFoundry Foundation

Versions Affected

*Severity is Critical unless otherwise noted.

UAA

– All versions through v77.30.0 (inclusive)

cf-deployment

– All versions through v48.9.0  (inclusive)

Description

A user authenticating through a federated OIDC provider can be granted the `uaa.admin` scope even when the operator has restricted that provider to a narrow scope prefix via `externalGroupsWhitelist`.

Preconditions

– An OIDC identity provider configured with `groupMappingMode: AS_SCOPES` and a wildcard `externalGroupsWhitelist` entry.

Mitigation

Users of affected products are strongly encouraged to follow the mitigations below.

The Cloud Foundry project recommends upgrading the following releases:


Uaa
– Upgrade UAA version to v77.31.0 or greater

cf-deployment
– Upgrade cf-deployment version to v48.10.0 or greater

Credit

This issue was responsibly reported by Tanzu at Broadcom

History

Initial vulnerability report published.

Cloud Foundry Foundation Security Team Profile Image

Cloud Foundry Foundation Security Team, AUTHOR

SEE ALL ARTICLES