Description
A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.
Published: 2026-09-11
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

A flaw in the UAA allows users authenticated through a federated OIDC provider to obtain the u provider using the externalGroupsWhitelist setting. The problem surfaces when the OIDC identity provider is configured with groupMappingMode: AS_SCOPES and the whitelist contains a wildcard entry (e.g., '*'). Because the scope grant logic incorrectly interprets the wildcard as authorizing all scopes, an attacker can be granted full administrative rights within UAA, enabling creation or modification of resources, encryption keys, or other sensitive data.

Affected Systems

The vulnerability affects installations of Cloud Foundry. No specific version details are listed in the advisory, so administrators should confirm that their deployments include the fix that addresses CVE-2026-47839.

Risk and Exploitability

The CVSS score of 9.2 indicates a critical risk. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, implying no public exploitation yet. However, any environment that relies on an externalGroupsWhitelist entry containing a wildcard under groupMapping, as the flaw can be exploited by an attacker simply by authenticating through a misconfigured federated OIDC provider.

Generated by OpenCVE AI on September 11, 2026 at 11:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update your Cloud Foundry Foundation UAA and cf-deployment installations to the latest releases that incorporate the security fix for CVE-2026-47839.
  • In the OIDC identity provider configuration, remove wildcard (*) entries from the externalGroupsWhitelist or replace them with a list of explicitly allowed groups.
  • If the application does not require scope-based mapping, change groupMappingMode from AS_SCOPES to AS_IDS to reduce the attack surface.

Generated by OpenCVE AI on September 11, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cloudfoundry
Cloudfoundry cf-deployment
Cloudfoundry uaa
Vendors & Products Cloudfoundry
Cloudfoundry cf-deployment
Cloudfoundry uaa

Fri, 11 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 11 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.
Title Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cloudfoundry Cf-deployment Uaa
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-09-11T14:24:54.282Z

Reserved: 2026-05-20T10:00:51.003Z

Link: CVE-2026-47839

cve-icon Vulnrichment

Updated: 2026-09-11T13:02:03.165Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T10:16:51.567

Modified: 2026-09-18T19:21:34.307

Link: CVE-2026-47839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:15:14Z

Weaknesses