B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

CVE-2026-41005 - UAA accepts SAML Encrypted Assertions authentication bypass

CVE ID :CVE-2026-41005 Published : June 11, 2026, 8:03 p.m. | 1 hour, 1 minute ago Description :Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the...

Original-Artikel öffnen Zurück zur Übersicht