CVE-2026-40965
Cloud Foundry UAA versions v76.12.0 through v78.12.0 expose EC private keys via the /token_keys endpoint, allowing attackers to forge JWT tokens. The flaw only affects deployments using elliptic‑curve keys for JWT signing; RSA configurations are safe. Upgrading to a fixed version removes the exposure.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Cloud Foundry UAA (and CF Deployment) that use EC keys for JWT signing.
Real-world impact
Attackers could obtain private signing keys and create fraudulent tokens, potentially gaining unauthorized access to protected resources.
Why this severity
CVSS v4.0 base score 10.0 (Critical) due to network‑adjacent, low‑complexity attack with high impact on confidentiality and integrity.
What to do about it
- 01Upgrade Cloud Foundry UAA to version v78.13.0 or later.
- 02If you are using CF Deployment, upgrade to version v56.1.0 or later (which bundles the fixed UAA).
NVD-referenced vendor advisory
Timeline
- Jun 1, 2026 · Jun 1, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.