Impact
A flaw in the UAA allows users authenticated through a federated OIDC provider to obtain the u provider using the externalGroupsWhitelist setting. The problem surfaces when the OIDC identity provider is configured with groupMappingMode: AS_SCOPES and the whitelist contains a wildcard entry (e.g., '*'). Because the scope grant logic incorrectly interprets the wildcard as authorizing all scopes, an attacker can be granted full administrative rights within UAA, enabling creation or modification of resources, encryption keys, or other sensitive data.
Affected Systems
The vulnerability affects installations of Cloud Foundry. No specific version details are listed in the advisory, so administrators should confirm that their deployments include the fix that addresses CVE-2026-47839.
Risk and Exploitability
The CVSS score of 9.2 indicates a critical risk. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, implying no public exploitation yet. However, any environment that relies on an externalGroupsWhitelist entry containing a wildcard under groupMapping, as the flaw can be exploited by an attacker simply by authenticating through a misconfigured federated OIDC provider.
OpenCVE Enrichment