---
id: CVE-2026-59358
title: >-
  Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry
  UAA allows a remote, authenticated attacker holding a valid user access token
  to obtain a fully-privileged client_credentials token for the OAuth client
  that …
summary: >-
  Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry
  UAA allows a remote, authenticated attacker holding a valid user access token
  to obtain a fully-privileged client_credentials token for the OAuth client
  that …
severity: high
cvss: 7.6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-287
vendor: Cloud Foundry
product: UAA
affected:
  - UAA >= 3.7.0 <= 79.6.0
  - cf-deployment <= 60.4.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T07:16:59.460'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59358'
references:
  - url: >-
      https://www.cloudfoundry.org/blog/cve-2026-59358-uaa-oauth-token-endpoint-vulnerability-allows-user-access-token-reuse-for-client_credentials-grant-type/
    label: security@vmware.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-06T07:49:23.044Z'
---

## Overview

Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated attacker holding a valid user access token to obtain a fully-privileged client_credentials token for the OAuth client that issued it, by presenting the user token as an OAuth 2.0 Bearer credential on a client_credentials grant request in place of the client’s configured secret.



UAA’s client_credentials handling does not verify that the Bearer credential supplied for client authentication is actually a client credential (a client secret or a valid configured client authentication method); it accepts any valid access token whose client_id matches the request. A token obtained by a normal end user through a public authorization_code + PKCE flow — scoped only to uaa.user, carrying a user_id, and recording client_auth_method=none — satisfies this check. That user token cannot itself administer OAuth clients (POST /oauth/clients correctly returns 403), but when replayed as Bearer authentication on a client_credentials request for the same client, UAA issues a new client-only token carrying the client’s full authorities, such as clients.write. An attacker can use that token to create arbitrary new OAuth clients, including clients with attacker-chosen authorities, without ever possessing the client’s actual secret.



Exploitation requires a valid user access token (the attacker’s own) for a client that is configured to support both a public, user-facing authorization flow and the client_credentials grant type on the same client_id — a non-default combination. Practical impact scales with the authorities assigned to that client.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
