Improper Authentication in Cloud Foundry UAA OAuth Token Endpoint by Cloud Foundry
CVE-2026-59358

7.6HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-59358?

The OAuth token endpoint in Cloud Foundry UAA is affected by an improper authentication vulnerability. This issue allows a remote attacker, who possesses a valid user access token, to acquire a fully-privileged client_credentials token for the OAuth client by presenting their user token as an OAuth 2.0 Bearer credential. The vulnerability stems from UAA's failure to properly verify that the supplied Bearer credential is indeed a client credential. As a result, an attacker can exploit this vulnerability to gain excessive authorities within the system just by leveraging a regular user token acquired through standard authorization flows. This flaw has significant implications, particularly when the OAuth client is configured to accept both public user authorization flows and client_credentials grants for the same client_id.

Affected Version(s)

cf-deployment 0 <= 60.4.0

UAA 3.7.0 <= 79.6.0

cf-deployment 60.5.0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.