CVE-2026-22734Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2.0 bearer assertions that are neither signed nor encrypted. This issue affects UUA from v77.30.0 to v78.7.0 (inclusive) and it affects CF Deployment from v48.7.0 to v54.14.0 (inclusive).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-17)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-16: 1Mentions · 2026-04-17: 2Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 204-1604-17
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-161
Disclosure1
2026-04-172
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-22734 Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists… https://www.cve.org/CVERecord?id=CVE-2026-22734

    Post summary

    CVE-2026-22734 is publicly disclosed as a bypass in Cloud Foundry UAA that lets attackers acquire arbitrary user tokens and access protected systems.

    0000063
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22734 Authentication Bypass in Cloud Foundry UAA via Unsigned SAML 2.0 Bearer Assertions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22734

    Post summary

    The text references CVE‑2026‑22734, noting an authentication bypass via unsigned SAML 2.0 bearer assertions, but provides only descriptive details without any PoC, exploit, or patch information.

    0000054
    4.0K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Disclosure

    CVE-2026-22734 | Cloud Foundry UUA | Vulnerability Description Cloud Foundry UUA SAML 2.0 signature bypass allows unauth attackers to obtain tokens for any user and access UAA-protected systems by submitting unsigned, unencrypted SAML 2.0 bearer assertions when enabled for a client, affecting UUA v77.30.0 to v78.7.0 and CF Deployment v48.7.0 to v54.14.0. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Cloud Foundry UUA Affected Version: >= v77.21.0 and <= v78.8.0 Sources Research: https://www.cloudfoundry.org/blog/cve-2026-22734-uaa-saml-2-0-signature-bypass/

    Post summary

    Cloud Foundry UUA is vulnerable to a SAML 2.0 signature bypass that lets unauthenticated attackers obtain tokens; a patch is available, but no PoC or active exploitation has been reported.

    00000106
    8 followersView on X

Explore more