Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-47839: UAA permits federated login to gain admin access

CVE-2026-47839 · published 29 days ago
Summary

The UAA component in Cloud Foundry deployments can mistakenly grant users who sign in through an external OpenID Connect (OIDC) login full administrative rights, even when the system is configured to limit those users. This could let an unauthorized person change settings or view sensitive information. Install the latest Cloud Foundry security update and change the configuration to avoid using a wildcard group list.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
cloud foundry foundation uaa <= 77.30.0
cloud foundry foundation cf-deployment <= 48.9.0
Original advisory text
A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration...
A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-284Improper Access Control
Timeline
Published11 Sep 2026
Updated7 Oct 2026
First seen11 Sep 2026
Sources
CVE-2026-47839 · MITRE
Track software like this
Free during beta