Executive brief
CloudFoundry UAA, an identity management service, contains a security flaw in how it connects to LDAP directories for user authentication. An attacker positioned on the network between these systems can impersonate the directory server to steal administrative credentials and user passwords. This could allow an attacker to gain full administrative control over the CloudFoundry environment and access sensitive user data.
Technical details
A vulnerability exists in CloudFoundry UAA where LDAP StartTLS connections unconditionally disable hostname verification. A network attacker positioned between UAA and the LDAP directory can perform a man-in-the-middle (MitM) attack using any valid certificate from a trusted Certificate Authority (CA), even if it does not match the LDAP server's hostname. This allows the attacker to harvest LDAP bind passwords and end-user credentials during simple-bind authentication. Furthermore, the attacker can return forged LDAP group memberships to grant themselves administrative scopes within the UAA environment. The issue is resolved in UAA v78.13.0 and cf-deployment v56.2.0.
Affected products
- CloudFoundry Foundation UAA prior to v78.13.0
- CloudFoundry Foundation Cf-deployment prior to v56.2.0
Timeline
- 2026-07-08: advisory: Initial vulnerability report published by Cloud Foundry Foundation
- 2026-07-09: disclosed: CVE published to NVD dataset