Junglewise Threat Intelligence

CVE-2026-40964: Cloud Foundry cf-auth-proxy authentication bypass

CVE-2026-40964 · Severity: high · CVSS 7.5 · Published 2026-06-01

Vendors: Cloud Foundry Foundation.

Executive brief

A security flaw in Cloud Foundry's authentication proxy allows unauthorized individuals to bypass security checks and access sensitive system data. An attacker can gain full read access to all application logs and performance metrics across the entire platform. This could lead to the exposure of confidential business data or credentials inadvertently stored in logs, potentially compromising the privacy of all hosted applications.

Technical details

An authentication bypass vulnerability exists in the cf-auth-proxy component of Cloud Foundry Foundation installations. The flaw is rooted in improper validation of JSON Web Tokens (JWT), where the proxy incorrectly accepts self-minted tokens as valid 'logs.admin' credentials. An unauthenticated remote attacker can exploit this by crafting a malicious JWT to bypass authentication mechanisms. Successful exploitation provides the attacker with comprehensive read access to every log and metric for every application and platform component. The issue is resolved in log-cache_release v3.2.7 and CF Deployment v55.?.0.

Affected products

  • Cloud Foundry Foundation log-cache_release through v3.2.6
  • Cloud Foundry Foundation CF Deployment through v55.?.0

Timeline

  • 2026-05-22: advisory: Initial vulnerability report published by Cloud Foundry Foundation
  • 2026-06-01: disclosed: NVD publication date

References