CVE-2026-59358
Received Received - Intake

Authentication Bypass in Cloud Foundry UAA

Vulnerability report for CVE-2026-59358, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VMware

Description

Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated attacker holding a valid user access token to obtain a fully-privileged client_credentials token for the OAuth client that issued it, by presenting the user token as an OAuth 2.0 Bearer credential on a client_credentials grant request in place of the client’s configured secret. UAA’s client_credentials handling does not verify that the Bearer credential supplied for client authentication is actually a client credential (a client secret or a valid configured client authentication method); it accepts any valid access token whose client_id matches the request. A token obtained by a normal end user through a public authorization_code + PKCE flow — scoped only to uaa.user, carrying a user_id, and recording client_auth_method=none — satisfies this check. That user token cannot itself administer OAuth clients (POST /oauth/clients correctly returns 403), but when replayed as Bearer authentication on a client_credentials request for the same client, UAA issues a new client-only token carrying the client’s full authorities, such as clients.write. An attacker can use that token to create arbitrary new OAuth clients, including clients with attacker-chosen authorities, without ever possessing the client’s actual secret. Exploitation requires a valid user access token (the attacker’s own) for a client that is configured to support both a public, user-facing authorization flow and the client_credentials grant type on the same client_id — a non-default combination. Practical impact scales with the authorities assigned to that client.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Cloud Foundry UAA 3.7.0
Cloud Foundry cf-deployment 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-59358 is an improper authentication vulnerability in Cloud Foundry UAA's OAuth token endpoint. It allows a remote attacker with a valid user access token to obtain a privileged client_credentials token by misusing the token in place of a client secret during a client_credentials grant request. The flaw occurs because UAA does not verify if the Bearer credential is a proper client credential, accepting any valid access token with a matching client_id.

Exploitation requires a user token from a client configured to support both public user-facing flows and client_credentials grants, which is uncommon. The attacker can then create new OAuth clients with elevated privileges like clients.write.

Detection Guidance

To detect this vulnerability, audit OAuth client configurations to check if any client supports both a public user-facing authorization flow (like authorization_code + PKCE) and the client_credentials grant type simultaneously. Review UAA logs for unusual client_credentials token requests where Bearer tokens are used instead of client secrets.

Impact Analysis

If exploited, an attacker could gain unauthorized access to create arbitrary OAuth clients with elevated privileges, such as clients.write. This could allow them to register new clients, modify existing ones, or escalate their access within the system, potentially leading to full compromise of the Cloud Foundry environment.

Compliance Impact

This vulnerability could lead to unauthorized access and privilege escalation, which may violate compliance requirements for data protection and access control. For GDPR, it risks unauthorized processing of personal data. For HIPAA, it could allow unauthorized access to protected health information. Organizations must address this to maintain compliance.

Mitigation Strategies

Immediately upgrade UAA to version v79.7.0 or later and CF Deployment to v60.5.0 or later. As a temporary measure, audit OAuth clients to ensure no client supports both public flows and client_credentials grants. Restrict administrative authorities like clients.write to dedicated, non-public clients.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59358. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart