Description
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS.
Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.
Published: 2026-07-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker positioned between UAA and its LDAP directory to bypass hostname verification during StartTLS, a flaw classified as CWE‑297 (Improper Validation of Certificate Authority Path). By presenting any certificate from a trusted CA, the attacker can impersonate the directory, capture LDAP bind passwords and every end‑user password transmitted via simple‑bind authentication, and forge group memberships that grant admin scopes. This results in privilege escalation and credential theft for all users authenticated through LDAP over StartTLS.

Affected Systems

Affected deployments include the CloudFoundry Foundation’s Cf‑deployment versions earlier than 56.2.0 and CloudFoundry Foundation UAA versions earlier than 78.13.0. Any CloudFoundry installation that authenticates users against an LDAP directory over StartTLS is at risk.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to be in the network path between UAA and the LDAP server, enabling a man‑in‑the‑middle takeover. Once positioned, the attacker can establish a StartTLS session, supply a forged certificate to bypass hostname verification, read bind credentials, and alter group memberships to elevate privileges.

Generated by OpenCVE AI on July 28, 2026 at 08:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade UAA to version 78.13.0 or newer and Cf‑deployment to version 56.2.0 or newer to apply the official fix.
  • Disable LDAP StartTLS or enforce hostname verification on the LDAP client side until the upgrade can be performed, preventing attackers from bypassing authentication.
  • Restrict network access to the LDAP service to trusted hosts only, using firewalls to block potential man‑in‑the‑middle attackers.

Generated by OpenCVE AI on July 28, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-297

Fri, 17 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-297

Thu, 16 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
CWE-295

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
CWE-295

Mon, 13 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Sat, 11 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-640

Thu, 09 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-640

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Cloudfoundry
Cloudfoundry cf-deployment
Cloudfoundry uaa
Vendors & Products Cloudfoundry
Cloudfoundry cf-deployment
Cloudfoundry uaa

Thu, 09 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Description A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.
Title LDAP StartTLS unconditionally disables hostname verification
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Cloudfoundry Cf-deployment Uaa
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-09T12:49:24.260Z

Reserved: 2026-05-20T10:00:51.003Z

Link: CVE-2026-47840

cve-icon Vulnrichment

Updated: 2026-07-09T12:49:17.939Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses

No weakness.