CVE 8.6 HIGH

Cloud Foundry UAA SAML 2.0 Signature Bypass_CVE-2026-22734

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Description

Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that are neither signed nor encrypted. This issue affects UUA from v77.30.0 to v78.7.0 (inclusive) and it affects CF Deployment from v48.7.0 to v54.14.0 (inclusive).

AI Analysis

SAML 2.0 signature bypass vulnerability allowing attackers to obtain tokens for any user

Basic Information

ID CVE-2026-22734
Source vmware
Published Apr 16, 2026 at 23:33

Affected Product

Vendor Cloud Foundry
Product UUA
Version v77.21.0
Affected Versions Cloud Foundry UUA v77.21.0

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor Cloud Foundry
Product Cloud Foundry UUA
Version v77.30.0 to v78.7.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.