Back

HIGH

Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token

Published Jun 1, 2026

Description

Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token.

Affected versions: - log-cache_release: all versions through v3.2.6 (inclusive); fixed in v3.2.7 or later - CF Deployment: all versions through v55.?.0 (inclusive); fixed in v55.?.0 or later (bundles log-cache_release v3.2.7)

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner vmware
Published Jun 1, 2026
Updated Jun 11, 2026
Reserved Apr 16, 2026

CISA Vulnrichment

Updated Jun 2, 2026

NVD

Status Awaiting Analysis
Modified Jul 22, 2026

Red Hat

No data

ENISA EUVD

Assigner vmware
Published Jun 1, 2026
Updated Jun 11, 2026

GitHub

No data