PT-2026-56709 · Uaa+1 · Uaa+1
CVE-2026-47840
·
Published
2026-07-09
·
Updated
2026-07-10
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
UAA versions prior to v78.13.0
Cf-deployment versions prior to v56.2.0
Description
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA. This allows the attacker to harvest the LDAP bind password and all end-user passwords transmitted during simple-bind authentication. Additionally, the attacker can return forged group memberships to grant themselves admin scopes. This issue affects deployments that authenticate users against LDAP over StartTLS, a protocol used to upgrade an insecure connection to a secure one using TLS.
Recommendations
Update UAA to version v78.13.0 or later.
Update Cf-deployment to version v56.2.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cf-Deployment
Uaa