CVE-2019-11279: Cloudfoundry Uaa Release

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.

Affected products

Published 2019-09-26. Last modified 2026-06-17.