CVE-2026-47839: Federated OIDC Users Can Bypass externalGroupsWhitelist to Gain uaa.admin

Published Sep 11, 2026
·
Updated

A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses groupMappingMode: ASSCOPES with a wildcard externalGroupsWhitelist entry.

Affected Software

1 affected component
Pivotal Cloud Foundry UAA

Event History

Sep 11, 2026
CVE Published
via MITRE·09:14 AM
Data Sourced
via MITRE·09:14 AM
Description

Frequently Asked Questions

1

Which deployments are affected by this issue?

The issue affects Pivotal Cloud Foundry UAA deployments with a federated OIDC identity provider configured with groupMappingMode: AS_SCOPES and a wildcard entry in externalGroupsWhitelist. The provided information does not indicate that other group-mapping modes or non-wildcard whitelist configurations are affected.

2

What does an attacker need to exploit the vulnerability?

An attacker needs to authenticate through the affected federated OIDC provider. Under the vulnerable configuration, they may obtain the uaa.admin scope despite the operator's externalGroupsWhitelist restriction.

3

How can operators reduce exposure before a patch is available?

Avoid the affected configuration combination: groupMappingMode: AS_SCOPES with a wildcard externalGroupsWhitelist entry for a federated OIDC provider. Review federated provider settings and remove or replace wildcard whitelist entries where possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203