logo

Cloud Foundry UAA Vulnerability Enables SAML Authentication Bypass

ID: 0b6c3ae0-b405-533b-a461-65f1e42b3739

STIX ID: report--0b6c3ae0-b405-533b-a461-65f1e42b3739

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Do Son

...
...

**Cloud Foundry UAA (CVE-2026-41005)** — A critical SAML authentication bypass (CVSS 9.0) allows attackers to craft encrypted but unsigned SAML assertions that UAA accepts as authentic, affecting uaa_release v2.0.0 through v78.13.0 and CF Deployment up to v56.1.0; administrators should upgrade to uaa_release v78.15.0 (or CF Deployment v57.0.0+) and consider disabling unsigned-assertion acceptance as a stopgap.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.