Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token.
Affected versions:
- log-cache_release: all versions through v3.2.6 (inclusive); fixed in v3.2.7 or later
- CF Deployment: all versions through v55.?.0 (inclusive); fixed in v55.?.0 or later (bundles log-cache_release v3.2.7)
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloudfoundry
Cloudfoundry cf-deployment Cloudfoundry log-cache Release |
|
| Vendors & Products |
Cloudfoundry
Cloudfoundry cf-deployment Cloudfoundry log-cache Release |
Tue, 02 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Access to Cloud Foundry Logs via cf-auth-proxy JWT Bypass |
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: - log-cache_release: all versions through v3.2.6 (inclusive); fixed in v3.2.7 or later - CF Deployment: all versions through v55.?.0 (inclusive); fixed in v55.?.0 or later (bundles log-cache_release v3.2.7) | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published: 2026-06-01T21:02:26.532Z
Updated: 2026-06-02T13:11:52.780Z
Reserved: 2026-04-16T02:18:56.132Z
Link: CVE-2026-40964
Updated: 2026-06-02T13:11:44.735Z
Status : Awaiting Analysis
Published: 2026-06-01T22:16:25.463
Modified: 2026-06-02T14:01:54.893
Link: CVE-2026-40964
No data.