PT-2026-94384 · Steeltoe · Steeltoe

CVE-2026-81868

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Steeltoe versions prior to 4.3.0
Description Steeltoe.Security.Authorization.Certificate deployments using AddOrgAndSpacePolicies() and UseCertificateAuthorization() trust the public certificate provided in the X-Client-Cert request header without verifying possession of the corresponding private key. Because common Cloud Foundry routers do not remove this header from inbound requests, an attacker who obtains a public certificate of an application instance within the target organization or space can spoof the X-Client-Cert header. This allows the attacker to bypass SameOrg and SameSpace authorization policies and gain unauthorized access to protected endpoints for the duration of the certificate validity period, provided that inbound requests are not restricted to a known trusted proxy source IP.
Recommendations Update to version 4.3.0. Restrict UseCertificateForwarding to trusted proxy source IPs using ForwardedHeadersOptions.KnownProxies and KnownNetworks. Change the forwarding header to X-Forwarded-Client-Cert to ensure Cloud Foundry Gorouter and Envoy header stripping mechanisms apply to inbound untrusted requests. Add a secondary authorization layer, such as a shared secret or mutual TLS at the proxy layer, for sensitive endpoints. Ensure the application is not bound to a public route unless explicitly required, utilizing Cloud Foundry internal routes and container-to-container network policies to limit network access.

Exploit

Fix

Improper Certificate Validation

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81868
GHSA-5MQ7-RWHJ-4FH9

Affected Products

Steeltoe