CVE Explorer
CVE-2026-41005
Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or responses that were unsigned but contained encrypted content could still be accepted. Encryption uses the SP's public key from published metadata, therefore, any party, not only a t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","product":"CF Deployment","vendor":"Cloud Foundry","versions":[{"lessThan":"57.0.0","status":"affected","version":"0.0.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4e5516c40c7b9f49328b71732e86296c348901d65aa58cde4d9af26417ae1296 · sha256:5a82c7292e9b8712… · /containers/cna/affected/1
{"defaultStatus":"unaffected","product":"UAA","vendor":"Cloud Foundry","versions":[{"lessThan":"78.14.0","status":"affected","version":"2.0.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4e5516c40c7b9f49328b71732e86296c348901d65aa58cde4d9af26417ae1296 · sha256:5a82c7292e9b8712… · /containers/cna/affected/0
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","product":"CF Deployment","vendor":"Cloud Foundry","versions":[{"lessThan":"57.0.0","status":"affected","version":"0.0.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4e5516c40c7b9f49328b71732e86296c348901d65aa58cde4d9af26417ae1296 · sha256:5a82c7292e9b8712… · /containers/cna/affected/1
{"defaultStatus":"unaffected","product":"UAA","vendor":"Cloud Foundry","versions":[{"lessThan":"78.14.0","status":"affected","version":"2.0.0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4e5516c40c7b9f49328b71732e86296c348901d65aa58cde4d9af26417ae1296 · sha256:5a82c7292e9b8712… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4e5516c40c7b9f49328b71732e86296c348901d65aa58cde4d9af26417ae1296 · sha256:5a82c7292e9b8712… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4e5516c40c7b9f49328b71732e86296c348901d65aa58cde4d9af26417ae1296 · sha256:5a82c7292e9b8712… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.cloudfoundry.org/blog/cve-2026-41005-uaa-accepts-saml-encrypted-assertions-authentication-bypass/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4e5516c40c7b9f49328b71732e86296c348901d65aa58cde4d9af26417ae1296 · sha256:5a82c7292e9b8712… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.