CVE-2026-41005: Cloud Foundry UAA SAML Signature Bypass
ID: 069e6957-9b29-5507-9064-84bedca1f15c
STIX ID: report--069e6957-9b29-5507-9064-84bedca1f15c
Feed Name: CosmicBytez Labs
Threat Score
**CVE-2026-41005 — Cloud Foundry UAA SAML authentication bypass:** A critical (CVSS 9.0) vulnerability allows an attacker who can obtain the SP encryption key and reach UAA SAML endpoints to forge encrypted but unsigned SAML assertions and gain authenticated access, including impersonation of administrators and issuance of OAuth tokens; primary remediation is to set wantAssertionSigned=true, rotate SP keys if exposed, and apply vendor patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
