CVE-2026-22723: Cloudfoundry Cf-Deployment
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
Affected products
- Cloudfoundry Cf-Deployment: after 48.7.0, up to and including 54.11.0
- Cloudfoundry Uaa-Release: from 77.30.0, before 78.8.0 (fixed in 78.8.0)
Published 2026-03-05. Last modified 2026-06-17.