๐Ÿ” CVE Alert

CVE-2026-40965

CRITICAL 10.0
CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
13th

Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed through the public /token_keys endpoint. This endpoint is designed to provide public key material for JWT token verification but incorrectly exposes private key components for EC keys. The vulnerability affects deployments using EC keys for JWT token signing. The vulnerability does not affect RSA key configurations, only deployments using EC keys for JWT signing. Affected versions: - uaa_release: v76.12.0 through v78.12.0 (inclusive); fixed in v78.13.0 or later - CF Deployment: v30.0.0 through v56.0.0 (inclusive); fixed in v56.1.0 or later (bundles uaa_release v78.13.0)

CWE CWE-200
Vendor cloud foundry foundation
Product uaa_release
Published Jun 1, 2026
Last Updated Jun 3, 2026
Stay Ahead of the Next One

Get instant alerts for cloud foundry foundation uaa_release

Be the first to know when new critical vulnerabilities affecting cloud foundry foundation uaa_release are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

Cloud Foundry Foundation / uaa_release
76.12.0 < 78.13.0
Cloud Foundry Foundation / CF Deployment
30.0.0 < 56.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cloudfoundry.org: https://www.cloudfoundry.org/blog/cve-2026-40965-uaa-ec-private-key-disclosure/