Junglewise Threat Intelligence

CVE-2026-59335: Cloud Foundry UAA authorization bypass via case sensitivity in identity zone endpoint

CVE-2026-59335 · Severity: high · CVSS 8.7 · Published 2026-08-25

Technologies: Cloud Foundry UAA. Vendors: Cloud Foundry.

Executive brief

Cloud Foundry UAA is an authentication and authorization service that manages identity and access control for Cloud Foundry deployments. This vulnerability allows an authenticated attacker with zone-management authority to bypass authorization checks and modify the system identity zone by using uppercase zone identifiers, exploiting a case-sensitivity mismatch between the authorization layer and MySQL database. A successful exploit gives the attacker control over the JWT signing key, enabling token forgery and complete takeover of the UAA deployment and all protected resources.

Technical details

The vulnerability is a case-sensitivity mismatch (CWE-178) in the Identity Zone Endpoint authorization check. The authorization layer performs case-sensitive comparison against the system zone identifier ("uaa"), but MySQL's default collation resolves identifiers case-insensitively. An authenticated attacker with zones.write authority can bypass the restriction preventing access to the privileged uaa system zone by using non-lowercase forms (e.g., "UAA") in the request path and body. The authorization check fails to recognize the non-lowercase variant as the system zone, but the database resolves it correctly and executes the request against the real system zone record. This allows the attacker to overwrite the system zone's JWT signing key with attacker-controlled material and forge JWTs claiming admin scopes. The vulnerability only affects UAA deployments using MySQL with default collation; PostgreSQL and HSQLDB backends are not affected. Patches are available in UAA v78.16.0 and CF Deployment v57.0.0 or later.

Affected products

  • Cloud Foundry UAA All versions prior to v78.16.0
  • Cloud Foundry CF Deployment All versions prior to v57.0.0

Timeline

  • 2026-08-24: disclosed

References

Related threats