CVE-2026-59357: medium-severity vulnerability in Cloud Foundry UAA
Self-UAA OIDC Configuration allows JWT injection to establish unauthorized sessions
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenticated external-OIDC browser session, via submitting a UAA access token or a cross-client ID token as the callback’s id_token parameter.
The issue only manifests when a UAA zone is configured with an OIDC identity provider whose issuer exactly matches that zone’s own /oauth/token endpoint (a “self-UAA” OIDC configuration). In this configuration, the callback takes a supplied id_token directly instead of requiring the authorization code exchange, and does not verify that the token was actually issued as an ID token for the specific self-OIDC relying-party client. An attacker holding any valid UAA JWT for themselves — including a plain access token with only uaa.user scope, or a valid ID token issued to an unrelated client such as cf — can present it as the callback’s id_token and be authenticated into a mapped local (“shadow”) account. Because the resulting session is not verified against the originating token’s true audience or user_id, its effective privilege depends entirely on the shadow account’s group memberships, which can include administrative scopes such as clients.write.
Exploitation requires a valid UAA user JWT, a valid browser login state for the target zone, and the presence of a self-referential OIDC provider configuration — this is not a pre-authentication vulnerability, and does not by itself grant privileges beyond those already held by the mapped shadow account.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Related CVEs — Cloud Foundry UAA
In the same product, most dangerous first.
CVE-2018-15761CRITICALUAA Privilege EscalationEPSS 1.7%CVE-2018-11082MEDIUMCloud Foundry UAA MFA does not prevent brute force of MFA codeEPSS 1.1%CVE-2019-3801HIGHJava Projects using HTTP to fetch dependenciesEPSS 0.6%CVE-2026-59335HIGHCase-Sensitive Authorization Check Bypass via Identity Zone ID Case Manipulation Leads to Full UAA CompromiseEPSS 0.5%CVE-2020-5402HIGHUAA fails to check the state parameter when authenticating with external IDPsEPSS 0.5%CVE-2026-59358HIGHUAA OAuth Token Endpoint Vulnerability allows user access token reuse for client_credentials grant typeEPSS 0.3%