CVE-2026-41005
Last modified
CVE-2026-41005 is a critical-severity vulnerability rated 9/10 on the CVSS scale. Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or responses that were unsigned but contained encrypted content could still be accepted. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or responses that were unsigned but contained encrypted content could still be accepted. Encryption uses the SP's public key from published metadata, therefore, any party, not only a trusted IdP, can produce ciphertext UAA can decrypt; successful decryption therefore does not prove the IdP issued the message. Affected versions: Cloud Foundry UAA (uaa_release) 2.0.0 through 78.13.0. Cloud Foundry CF Deployment all versions through 56.1.0.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Cloud Foundry | UAA | >= 2.0.0, < 78.14.0 |
| Cloud Foundry | CF Deployment | >= 0.0.0, < 57.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-41005?
How severe is CVE-2026-41005?
How do I fix CVE-2026-41005?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-4100The Paid Memberships Pro plugin for WordPress is vulnerable …7.1
- CVE-2026-41000Wss4jSecurityInterceptor did not consistently wire Apache WS…3.7
- CVE-2026-41001Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fix…5.3
- CVE-2026-41002The base directory (`spring.cloud.config.server.git.basedir`…8.1
- CVE-2026-41003An attacker able to influence values in RelyingPartyRegistra…5.4
- CVE-2026-41004When enabling trace logging in Spring Cloud Config Server se…4.4
- CVE-2026-41006Spring HATEOAS's internal PropertyUtils.createObjectFromProp…7.5
- CVE-2026-41007Spring HATEOAS maintains an unbounded static cache of String…7.5
- CVE-2026-41008Spring Security Authorization Server's authorization endpoin…6.1
- CVE-2026-41009When the director sends a long-running request (e.g. compile…5.8
- CVE-2026-4101IBM Verify Identity Access Container 11.0 through 11.0.2 and…9.8
- CVE-2026-41010ReleaseJob#unpack builds job_dir = File.join(@release_dir, '…8.7
Are you affected by CVE-2026-41005?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
