Severity
CVSSv4.0 – 7.7 — CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVSSv3.1 – 8.3 — CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Vendor
CloudFoundry Foundation
Versions Affected
*Severity is High unless otherwise noted.
UAA
- All versions prior to v78.16.0
CF Deployment
- All versions prior to v57.0.0
Description
An authorization bypass vulnerability in Cloud Foundry UAA’s identity zone management API allows an authenticated caller holding zone-management authority to modify the system identity zone. A successful exploit gives the attacker control over the system zone’s JWT signing key configuration, enabling the forgery of tokens with arbitrary authorities and full takeover of the UAA deployment and all resources it protects.
This vulnerability is only exploitable on UAA deployments backed by MySQL (any version) using the default database collation. Deployments using PostgreSQL or HSQLDB are not affected.
Mitigation
Users of affected products are strongly encouraged to follow the mitigations below.
The Cloud Foundry project recommends upgrading the following releases:
UAA
- Upgrade UAA versions to v78.16.0 or greater
CF Deployment
- Upgrade cf-deployment version to v57.0.0 or greater
- Includes UAA v78.16.0
Credit
This issue was responsibly reported by Doyensec.
History
Aug 24 2026: Initial vulnerability report published.
