AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-47840

HIGH · CVSS 7.5 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

A vulnerability exists in UAA versions prior to v78.13.0 and Cf-deployment versions prior to v56.2.0, allowing network attackers to impersonate the LDAP directory using any trusted CA certificate. This exploitation can lead to the harvesting of LDAP bind passwords and end-user passwords during simple-bind authentication, as well as the ability to manipulate group memberships to gain administrative access. Organizations utilizing LDAP over StartTLS for user authentication should prioritize patching to mitigate this critical risk.

CVE
CVE-2026-47840
Severity
HIGH
CVSS
7.5
EPSS
0.13%

Original NVD Description

A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.