CVE-2026-47839

Summary

A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.

Affected Software

VendorProductVersion RangeStatus
Cloud Foundry FoundationUAA0 <= 77.30.0affected
Cloud Foundry FoundationUAA77.31.0unaffected
Cloud Foundry Foundationcf-deployment0 <= 48.9.0affected
Cloud Foundry Foundationcf-deployment48.10.0unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References