Cloud Foundry UAA Vulnerability Enables SAML Authentication Bypass
ID: 0b6c3ae0-b405-533b-a461-65f1e42b3739
STIX ID: report--0b6c3ae0-b405-533b-a461-65f1e42b3739
Feed Name: securityonline.info
Threat Score
**Cloud Foundry UAA (CVE-2026-41005)** — A critical SAML authentication bypass (CVSS 9.0) allows attackers to craft encrypted but unsigned SAML assertions that UAA accepts as authentic, affecting uaa_release v2.0.0 through v78.13.0 and CF Deployment up to v56.1.0; administrators should upgrade to uaa_release v78.15.0 (or CF Deployment v57.0.0+) and consider disabling unsigned-assertion acceptance as a stopgap.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
