CVE-2026-22723

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/03/2026
Last modified:
17/03/2026

Description

Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* 48.7.0 (excluding) 54.11.0 (including)
cpe:2.3:a:cloudfoundry:uaa-release:*:*:*:*:*:*:*:* 77.30.0 (including) 78.8.0 (excluding)