Authentication Bypass in Cloud Foundry UAA Impacts Service Provider Integrity
CVE-2026-41005

9CRITICAL

Key Information:

Vendor
CVE Published:
11 June 2026

What is CVE-2026-41005?

The vulnerability in Cloud Foundry UAA arises from improper handling of XML encryption, where the system mistakenly treats encrypted content as a valid substitute for authenticity provided by XML signatures. This flaw is present in two specific SAML flows: the OAuth 2.0 SAML2 bearer grant and browser SSO, particularly when wantAssertionSigned is set to false. Unsigned assertions that contain encrypted content can be processed by UAA, raising serious concerns about the trustworthiness of the identity provider (IdP). Since the encryption uses the service provider's public key, any entity could create ciphertext that UAA would decrypt, leading to unauthorized access.

Affected Version(s)

CF Deployment 0.0.0 < 57.0.0

UAA 2.0.0 < 78.14.0

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.