8.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Description
Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that are neither signed nor encrypted. This issue affects UUA from v77.30.0 to v78.7.0 (inclusive) and it affects CF Deployment from v48.7.0 to v54.14.0 (inclusive).
AI Analysis
SAML 2.0 signature bypass vulnerability allowing attackers to obtain tokens for any user
Basic Information
ID
CVE-2026-22734
Source
vmware
Published
Apr 16, 2026 at 23:33
Affected Product
Vendor
Cloud Foundry
Product
UUA
Version
v77.21.0
Affected Versions
Cloud Foundry UUA v77.21.0
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
Cloud Foundry
Product
Cloud Foundry UUA
Version
v77.30.0 to v78.7.0