Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
PUBLISHED5.2
UAA User Token Revocation logic error
Affected products
Cloudfoundry Foundation
UAA
<= v78.7.0 - AFFECTED
References
GitHub Security Advisories
GHSA-6wcw-r64p-qrrw
Inappropriate user token revocation due to a logic error in the token revocation endpoint...
https://github.com/advisories/GHSA-6wcw-r64p-qrrwInappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-22723Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-22723",
"assignerOrgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
"assignerShortName": "vmware",
"dateUpdated": "2026-03-05T20:40:27.743Z",
"dateReserved": "2026-01-09T06:54:36.841Z",
"datePublished": "2026-03-05T20:40:27.743Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d",
"shortName": "vmware",
"dateUpdated": "2026-03-05T20:40:27.743Z"
},
"title": "UAA User Token Revocation logic error",
"descriptions": [
{
"lang": "en",
"value": "Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "<span style=\"background-color: rgb(255, 255, 255);\">Inappropriate user token revocation <span style=\"background-color: rgb(255, 255, 255);\">due to a logic error in the token revocation endpoint implementation </span>in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment <span style=\"background-color: rgb(255, 255, 255);\">v48.7.0 to v54.10.0.</span></span><br>"
}
]
}
],
"affected": [
{
"vendor": "Cloudfoundry Foundation",
"product": "UAA",
"defaultStatus": "unaffected",
"versions": [
{
"version": "77.30.0",
"status": "affected",
"versionType": "custom",
"lessThanOrEqual": "v78.7.0"
}
]
}
],
"references": [
{
"url": "https://www.cloudfoundry.org/blog/cve-2026-22723-uaa-user-token-revocation/"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
}
}
]
}
}
}