{"id":"CVE-2026-47839","title":"A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration","summary":"A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an …","severity":"critical","cvss":9.2,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-284"],"vendor":"Cloud Foundry Foundation","product":"UAA","affected":["UAA <= 77.30.0","cf-deployment <= 48.9.0"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:21:34.307","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47839","references":[{"url":"https://www.cloudfoundry.org/blog/cve-2026-47839-federated-oidc-users-can-bypass-externalgroupswhitelist-to-gain-uaa-admin/","label":"security@vmware.com"}],"tags":["nvd","cve.org"],"epss":0.003,"epssPercentile":0.22936,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-11T12:59:13.491445Z"},"cvssSource":"cna","ingestedAt":"2026-09-11T18:53:56.566Z","slug":"CVE-2026-47839","body":"## Overview\n\nA vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":51,"depthScoreParts":{"impact":50.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}