PT-2026-48733 · Cloud Foundry · Cf-Deployment+1

CVE-2026-41005

·

Published

2026-06-11

·

Updated

2026-06-17

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry UAA versions 2.0.0 through 78.13.0 Cloud Foundry CF Deployment versions prior to 56.1.0
Description Cloud Foundry UAA incorrectly treats XML encryption to the Service Provider as a substitute for XML signatures from the Identity Provider in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. This allows unsigned assertions or responses containing encrypted content to be accepted. Because encryption uses the Service Provider's public key from published metadata, any party can produce ciphertext that UAA can decrypt, meaning successful decryption does not prove the Identity Provider issued the message.
Recommendations Update Cloud Foundry UAA to a version later than 78.13.0. Update Cloud Foundry CF Deployment to a version later than 56.1.0.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41005

Affected Products

Cf-Deployment
Cloud Foundry Uaa