AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-11279

HIGH · CVSS 8.8 EPSS 1.33%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-09-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-11279
Severity
HIGH
CVSS
8.8
EPSS
1.33%

Original NVD Description

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.