AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-11278

HIGH · CVSS 8.8 EPSS 1.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-09-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-11278
Severity
HIGH
CVSS
8.8
EPSS
1.34%

Original NVD Description

CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should not have.