PT-2026-48733 · Cloud Foundry · Cf-Deployment+1
CVE-2026-41005
·
Published
2026-06-11
·
Updated
2026-06-17
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry UAA versions 2.0.0 through 78.13.0
Cloud Foundry CF Deployment versions prior to 56.1.0
Description
Cloud Foundry UAA incorrectly treats XML encryption to the Service Provider as a substitute for XML signatures from the Identity Provider in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when
wantAssertionSigned is set to false. This allows unsigned assertions or responses containing encrypted content to be accepted. Because encryption uses the Service Provider's public key from published metadata, any party can produce ciphertext that UAA can decrypt, meaning successful decryption does not prove the Identity Provider issued the message.Recommendations
Update Cloud Foundry UAA to a version later than 78.13.0.
Update Cloud Foundry CF Deployment to a version later than 56.1.0.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cf-Deployment
Cloud Foundry Uaa