CVE-2026-47839
Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.
| Vendor | cloud foundry foundation |
| Product | uaa |
| Published | Sep 11, 2026 |
| Last Updated | Sep 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for cloud foundry foundation uaa
Be the first to know when new unknown vulnerabilities affecting cloud foundry foundation uaa are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Cloud Foundry Foundation / UAA
0 โค 77.30.0
Cloud Foundry Foundation / cf-deployment
0 โค 48.9.0
References
Credits
Tanzu at Broadcom (responsible disclosure)