Executive brief
CloudFoundry User Authentication and Authorization (UAA) is a service used to manage identity and access for cloud applications. A logic error in how the system handles session cancellations allows an authenticated user to inappropriately revoke tokens, potentially leading to a denial of service for other users. This could disrupt business operations by preventing legitimate users from accessing their cloud-based applications and services.
Technical details
A logic error exists in the token revocation endpoint of CloudFoundry UAA. An authenticated attacker with network access can exploit this flaw to revoke user tokens that they should not have the authority to manage. This vulnerability is classified as a Protection Mechanism Failure (CWE-693) and results in a denial of service (DoS) for the affected user sessions. The issue is present in UAA Release versions v77.30.0 through v78.7.0 and CF Deployment versions v48.7.0 through v54.10.0. Patches are available in UAA Release v78.8.0 and CF Deployment v54.11.0.
Affected products
- CloudFoundry UAA Release v77.30.0 to v78.7.0
- CloudFoundry CF Deployment v48.7.0 to v54.10.0
Timeline
- 2026-02: other: Initial vulnerability report published internally
- 2026-03-05: advisory: Public advisory released by CloudFoundry Foundation
- 2026-03-05: patched: Fixes released in UAA v78.8.0 and CF Deployment v54.11.0