Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-47839: UAA permits federated login to gain admin access
CVE-2026-47839 · published 29 days ago
Summary
The UAA component in Cloud Foundry deployments can mistakenly grant users who sign in through an external OpenID Connect (OIDC) login full administrative rights, even when the system is configured to limit those users. This could let an unauthorized person change settings or view sensitive information. Install the latest Cloud Foundry security update and change the configuration to avoid using a wildcard group list.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cloud foundry foundation | uaa | <= 77.30.0 |
| cloud foundry foundation | cf-deployment | <= 48.9.0 |
Original advisory text
A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration...
A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.2
Critical
Type
CWE-284Improper Access Control
Timeline
Published11 Sep 2026
Updated7 Oct 2026
First seen11 Sep 2026
Track software like this
Free during beta