CVE-2026-59357
Received Received - Intake

Authentication Bypass via Self-OIDC in Cloud Foundry UAA

Vulnerability report for CVE-2026-59357, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VMware

Description

Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenticated external-OIDC browser session, via submitting a UAA access token or a cross-client ID token as the callback’s id_token parameter. The issue only manifests when a UAA zone is configured with an OIDC identity provider whose issuer exactly matches that zone’s own /oauth/token endpoint (a “self-UAA” OIDC configuration). In this configuration, the callback takes a supplied id_token directly instead of requiring the authorization code exchange, and does not verify that the token was actually issued as an ID token for the specific self-OIDC relying-party client. An attacker holding any valid UAA JWT for themselves — including a plain access token with only uaa.user scope, or a valid ID token issued to an unrelated client such as cf — can present it as the callback’s id_token and be authenticated into a mapped local (“shadow”) account. Because the resulting session is not verified against the originating token’s true audience or user_id, its effective privilege depends entirely on the shadow account’s group memberships, which can include administrative scopes such as clients.write. Exploitation requires a valid UAA user JWT, a valid browser login state for the target zone, and the presence of a self-referential OIDC provider configuration — this is not a pre-authentication vulnerability, and does not by itself grant privileges beyond those already held by the mapped shadow account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Cloud Foundry UAA 4.5.0
Cloud Foundry cf-deployment 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves insufficient verification of data authenticity in Cloud Foundry UAA's OIDC login callback. When a UAA zone uses a self-referential OIDC provider (issuer matches the zone's /oauth/token endpoint), an attacker with a valid UAA JWT can bypass OAuth authorization-code exchange by submitting it as the callback's id_token parameter. This allows unauthorized session establishment as a mapped local account.

Detection Guidance

Check UAA zone configurations for OIDC providers where the issuer URL matches the zone's /oauth/token endpoint. Review logs for callback requests containing id_token parameters with JWTs not originating from the standard OAuth flow.

Impact Analysis

An attacker could impersonate your account if they obtain your valid UAA JWT and your browser is logged into the target zone. They could gain access to your shadow account and potentially escalate privileges to administrative levels like clients.write, depending on your group memberships.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Administrative access gained through exploitation may result in unauthorized data modifications or deletions, further compromising compliance.

Mitigation Strategies

Upgrade UAA to v79.7.0 or later and cf-deployment to v60.5.0 or later. Disable any self-referential OIDC configurations where the issuer matches the /oauth/token endpoint. Monitor for unusual session establishment patterns in UAA logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59357. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart