CVE-2026-22723
Modified
Modified - Updated After Analysis
Logic Error in Cloudfoundry UAA Token Revocation Endpoint
Publication date: 2026-03-05
Last updated on: 2026-05-10
Assigner: VMware
Description
Description
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cloudfoundry | uaa-release | From 77.30.0 (inc) to 78.8.0 (exc) |
| cloudfoundry | cf-deployment | From 48.7.0 (exc) to 54.11.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-693 | The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. |
| CWE-640 | The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. |