CVE-2026-47840 Details
Description
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.
A vulnerability exists in Cloud Foundry UAA versions prior to v78.13.0 and in cf-deployment versions prior to v56.2.0. This vulnerability allows a network attacker positioned between UAA and its LDAP directory to impersonate the directory using any certificate from a trusted CA. The attacker can then harvest the LDAP bind password and all end-user passwords transmitted during simple-bind authentication. Additionally, the attacker can return forged group memberships that grant admin scopes. This issue affects deployments that authenticate users against LDAP over StartTLS.
Users are advised to upgrade UAA to version 78.13.0 or greater and to upgrade cf-deployment to version 56.1.0 or greater.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cloudfoundry.org/blog/cve-2026-47840-ldap-starttls-unconditionally-disables-hostname-verification/ | [email protected] |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |