Executive brief
Cloud Foundry User Authentication and Authorization (UAA) is a service used to manage identity and security tokens for cloud applications. A critical security flaw allows anyone on the network to view the private encryption keys used to sign security tokens when Elliptic Curve (EC) cryptography is used. An attacker could use these stolen keys to forge identity tokens, potentially gaining full administrative access to the cloud environment or impersonating any user.
Technical details
Cloud Foundry UAA contains an information disclosure vulnerability in the public /token_keys endpoint. While this endpoint is intended to provide public key material for JWT verification, it incorrectly includes private key components when Elliptic Curve (EC) keys are configured for token signing. A remote, unauthenticated attacker can access this endpoint over the network to retrieve the private keys. With these keys, an attacker can sign fraudulent JSON Web Tokens (JWTs), leading to complete authentication bypass and privilege escalation. This issue does not affect RSA key configurations. Patches are available in uaa_release v78.13.0 and CF Deployment v56.1.0.
Affected products
- Cloud Foundry UAA Release v76.12.0 through v78.12.0
- Cloud Foundry CF Deployment v30.0.0 through v56.0.0
Timeline
- 2026-05-13: advisory: Initial vulnerability report published by Cloud Foundry Foundation
- 2026-06-01: disclosed: CVE published to NVD dataset