Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-59358— UAA OAuth Token Endpoint Vulnerability allows user access token reuse for client_credentials grant type

Quick assessment

Affected
Cloud Foundry UAA
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

云发现平台用户账户和授权(Cloud Foundry UAA)的 OAuth 令牌端点存在不正确的身份验证漏洞(CWE-287)。持有有效用户访问令牌的远程攻击者,可以在针对 (客户端凭证)授权类型的请求中,将该用户令牌作为 OAuth 2.0 Bearer 凭证使用,从而获取由签发该用户令牌的 OAuth 客户端所对应的完全权限的 令牌。 UAA 在处理 时,未验证用于客户端身份认证的 Bearer 凭证实际上是否为客户端凭证(即客户端密钥或有效的配置认证方法),而是接受任何 与请求匹配的合法访问令牌。通过标准的

CVSS 7.6 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-59358

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
UAA OAuth Token Endpoint Vulnerability allows user access token reuse for client_credentials grant type
Source: CVE Program / CVE List V5
Vulnerability Description
Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated attacker holding a valid user access token to obtain a fully-privileged client_credentials token for the OAuth client that issued it, by presenting the user token as an OAuth 2.0 Bearer credential on a client_credentials grant request in place of the client’s configured secret. UAA’s client_credentials handling does not verify that the Bearer credential supplied for client authentication is actually a client credential (a client secret or a valid configured client authentication method); it accepts any valid access token whose client_id matches the request. A token obtained by a normal end user through a public authorization_code + PKCE flow — scoped only to uaa.user, carrying a user_id, and recording client_auth_method=none — satisfies this check. That user token cannot itself administer OAuth clients (POST /oauth/clients correctly returns 403), but when replayed as Bearer authentication on a client_credentials request for the same client, UAA issues a new client-only token carrying the client’s full authorities, such as clients.write. An attacker can use that token to create arbitrary new OAuth clients, including clients with attacker-chosen authorities, without ever possessing the client’s actual secret. Exploitation requires a valid user access token (the attacker’s own) for a client that is configured to support both a public, user-facing authorization flow and the client_credentials grant type on the same client_id — a non-default combination. Practical impact scales with the authorities assigned to that client.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cloud Foundry UAA 3.7.0 ~ 79.6.0 -
Cloud Foundry cf-deployment 0 ~ 60.4.0 -

II. Public POCs for CVE-2026-59358

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-59358

请登录查看更多情报信息。

Other References for CVE-2026-59358 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-59358

No comments yet


Leave a comment