logo

CVE-2026-41005: Cloud Foundry UAA SAML Signature Bypass

ID: 069e6957-9b29-5507-9064-84bedca1f15c

STIX ID: report--069e6957-9b29-5507-9064-84bedca1f15c

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-06-12

Date Updated: 2026-06-13

...
...

**CVE-2026-41005 — Cloud Foundry UAA SAML authentication bypass:** A critical (CVSS 9.0) vulnerability allows an attacker who can obtain the SP encryption key and reach UAA SAML endpoints to forge encrypted but unsigned SAML assertions and gain authenticated access, including impersonation of administrators and issuance of OAuth tokens; primary remediation is to set wantAssertionSigned=true, rotate SP keys if exposed, and apply vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.